Central Counterparty Risk in Automated Markets

Abstract

How much collateral and timely cash does a central counterparty need when closing a failed trader’s position moves market prices? We study automated markets whose reserve rule determines the proceeds of each liquidation. For fixed losses, a five-stage allocation has a unique, order-independent result and an exact condition for absorbing the remaining loss. Cash payments and reductions of unpaid profit claims contribute separately to that condition. A finite model of observations and payment deadlines then gives the exact initial cash needed for an executable settlement plan. When the common trading asset derives value from locked liquidity, forced withdrawals also change the resources supporting clearing. We identify where the coupled price and liquidity equations cease to determine a finite rate of change. On a specified declining branch, sufficient leverage produces finite-time collapse. External collateral and settlement rules that prevent clearing-induced withdrawals exclude that branch when the withdrawal and valuation elasticities have product below one. Position losses and declines in settlement-asset value remain. The supporting margin analysis bounds liquidation contagion and separates uncertainty about future losses from numerical integration error.

The author has a commercial interest in systems of the kind this paper describes.

1 Introduction

1.1 The clearing guarantee and the cash needed to perform it

A central counterparty becomes the buyer to each seller and the seller to each buyer under the applicable clearing agreement. Its guarantee places the contractual obligation to perform on the clearinghouse when a participant fails. The clearinghouse therefore needs resources to meet losses and cash available when payments fall due. This paper asks how those requirements change when selling a failed participant’s assets moves their price.

Consider the collateral-sale example developed in Section 6.5. An account owes 100 and has pledged assets quoted at 80. Those pledged assets are its collateral, available to meet the obligation subject to existing claims and priorities. Selling them yields 70 after price impact, so 30 remains unpaid. The quote suggested a 20 gap, but the sale itself added 10 to it. The clearinghouse must meet that remaining loss through other resources or a legally permitted reduction of claims. A reduction makes a creditor bear loss. It supplies no cash.

Timing creates another requirement even when total asset value is sufficient. In Example 6.7, a payment of 100 falls due at time 1. Available cash is 20, and securities produce another 80 only at time 2. The earlier payment still has a cash gap of 80. A timely facility can cover that gap, but its repayment must remain in the settlement plan. Appendix C computes the minimum initial cash that permits completion after every represented observation and deadline.

Margin is the collateral requirement imposed before losses occur. An account defaults in this paper’s clearing application when its current loss exceeds its available collateral. A default waterfall specifies the order in which the clearinghouse uses resources and reduces eligible claims after that default. Netting replaces specified gross obligations by their legally enforceable net amounts. Clearing here computes obligations and applies this waterfall within the clearing book. Settlement requires the resulting transfers to become final under the external payment system’s rules. The zero-residual theorem below states when the waterfall allocates the full loss, including any permitted claim reductions. The completion theorem states when an admitted payment plan has enough timely cash to perform its remaining obligations.

1.2 Why automated execution changes clearing risk

An automated market maker (AMM) exchanges assets held in a pool according to a specified reserve rule. A sale removes the asset used for payment and adds the asset being sold, changing the price of the next unit. The difference between the initial quoted price and the average execution price is slippage. Liquidity providers (LPs) supply these reserves and hold shares in the pool. Their withdrawals reduce the reserves available for later trades. We use central counterparty (CCP) for the clearinghouse.

The pools studied here exchange different assets against one common asset. We call the common asset the hub asset and each other asset a spoke asset. This arrangement connects otherwise separate pools through their common trading asset. If that asset also derives value from the liquidity locked in the pools, withdrawals can reduce collateral value and induce further withdrawals. We call this dependence endogenous value and the resulting price-withdrawal feedback reflexivity.

A second source of risk is an inaccurate model of losses occurring together. A collateralized debt obligation (CDO) divides a pool of debt into claims, called tranches, with different payment priorities. The historical comparison below concerns the dependence model used to value those claims. It does not treat their valuation as centrally cleared settlement.

Terra/Luna (May 2022) and Iron Finance (June 2021) collapsed through the same loop: the asset backing the system was valued partly by the liquidity locked in the system, so withdrawals cut the collateral value, which forced liquidations, which drove further withdrawals [14, 15, 17]. Own-token collateral creates the exchange-side instance of the same defect. In 2008, the pricing and rating of CDO tranches rested on a single Gaussian-copula correlation model [58] calibrated on a sample that contained no systemic default event; when the tail realised, the capital held against the senior tranches did not cover it [68, 69]. Two defects recur: collateral whose value is endogenous to the clearing system, and solvency resting on one correlation model.

A central counterparty (CCP) clearing trades executed on a hub-and-spoke AMM faces both defects in sharpened form, together with one structural advantage. The advantage: the price-impact function is deterministic and known to the clearinghouse. When a position is liquidated into an AMM pool with reserves (R_{\!M}, R_{\!B}), the realised slippage is a closed-form function of volume relative to reserves, not a distribution over an unobservable order-book state. The sharpened defect: if the hub asset’s valuation depends partly on liquidity locked in the spokes, the clearing and price-formation layers are coupled, and the feedback loop admits an exact dynamical-systems representation.

In this paper, clear means compute obligations and apply the waterfall inside the clearing book. It does not mean that an external settlement rail has made a final transfer.

AMM venues now clear leveraged derivatives without the margin methodology, waterfall design, and stress discipline of established CCP practice. Traditional CCP theory treats price impact stochastically (Standard Portfolio Analysis of Risk (SPAN) [7] shock scenarios applied to exogenous markets) and treats collateral value as independent of clearing decisions; neither assumption holds here. The Cont-Wagalath framework [4] for fire-sale contagion is the right starting point and requires specialisation to the AMM impact kernel; the Eisenberg-Noe framework [1] for network clearing is the natural comparison for the waterfall, which needs no fixed point once the losses entering it are fixed at clearing time; and the reflexive channel requires a model neither supplies.

Expected Shortfall (ES) is the average loss in a specified worst probability mass. At a tail mass of one percent, it averages the worst one percent of outcomes, taking the required fraction of any tied outcome. This measure helps size margin. A stated margin requirement still needs actual collateral funding. The waterfall can finally reduce unpaid profit claims through auto-deleveraging (ADL). These reductions are distinct from the cash resources collected at earlier stages.

The dynamics require a further distinction. A branch is a set of rates of change consistent with the simultaneous price and withdrawal equations. An impasse is a state where those equations lose the ability to determine a finite rate. A fold bifurcation would instead describe equilibria meeting and disappearing as a parameter changes. The classification below determines which of these mechanisms the model actually supports.

1.3 Contributions and adapted material

A settlement asset is the asset used to discharge obligations. A depeg is a deviation from its reference value. The loss bounds below consider downward deviations. A haircut credits collateral below its reference value to allow for deterioration and conversion costs.

The quantitative results use two elasticities. The parameter \lambda measures proportional liquidity withdrawal in response to a proportional price decline. For a power value function, \gamma measures the proportional value change produced by a proportional liquidity change. The factor \Gamma records the clearing layer’s additional effect on withdrawal-driven value loss. Their formal definitions appear in Section 9. A quadrature rule approximates an integral by a weighted finite sum. Its error matters when a numerical tail-loss estimate sets collateral.

Adapted CCP methods.

Portfolio margin with correlation-aware scenario aggregation (§3), the multi-stage default waterfall as a clearing operator (§6), compliance-tier margin recalculation (§7), and the multi-settlement-asset haircut model (§12) specialise well-established CCP designs [7, 8, 6] to the AMM-price-impact setting. The ES measure follows Acerbi-Tasche [60]. The waterfall is stated as a deterministic clearing operator: Theorem 6.12 gives existence, uniqueness, and the exact zero-residual condition, and Proposition 6.13 gives order-independence under simultaneous defaults. Neither is a fixed-point result of Eisenberg-Noe type, because the losses entering the waterfall are fixed at clearing time; the design is standard CCP practice, and the formal content is that the recursion is well defined and order-free.

Original contributions.

Three results are new: the deterministic fire-sale contagion bound (Theorem 8.4, §8), the impasse classification of the reflexive cascade with its finite-time collapse theorem (§§9-10), and the continuous-density Expected Shortfall analysis with quadrature-error control (§4). The last result applies a common loss functional to distinct laws: the venue’s price law supplies a pricing diagnostic, while calibrated physical laws supply margin. A fourth, exogenous-settlement severance (Theorem 11.2, §11), states in the coupled model the price-channel content of the cash-collateral discipline traditional CCPs already practice.

Under the settlement discipline of Definition 11.1 (collateral held in the settlement asset, LP shares and the hub asset ineligible, no clearing action withdrawing locked liquidity) no clearing action changes L, so the liquidation-leverage factor of Definition 9.2 is \Gamma = 1. This caps the reflexivity coefficient at the LP elasticity \lambda\gamma and, when that is below one, keeps every admissible trajectory subcritical (Corollary 11.6).

Its remaining content is the contrast with own-token and LP-share collateral, the closed-form gate bounds for the counter-cyclical buyback (Propositions 11.16-11.19), and the channels it does not remove: position losses, which the waterfall absorbs, spoke correlation, and a correlated-depeg residual.

A claim pack groups the claims and governing records supplied to the clearing calculation. Its records state which obligations may be combined and what evidence permits their settlement.

Four companion papers define the inputs at this paper’s boundary. One Entity in Many Jurisdictions defines the composed standing and lawful holder set [37]. Op: A Typed Bytecode for Compliance-Carrying Operations defines provider finality for each external leg [38]. Admissible Obligation Transitions defines per-claim consumption and the pack’s declared netting foundation [39]. Event-Collect BFT defines ledger confirmation [40]. This paper develops the multi-claim waterfall, settlement gate, and linked delivery-versus-payment consequences.

The institutional comparisons use the Principles for Financial Market Infrastructures (PFMI) and the European Market Infrastructure Regulation (EMIR). The institutional abbreviations CPMI and IOSCO denote the Committee on Payments and Market Infrastructures and the International Organization of Securities Commissions.

These sources distinguish participant margin, default resources, liquidity, and legal settlement. A skin-in-the-game tranche is the clearinghouse’s own dedicated equity, consumed before the shared default fund. Porting transfers client positions to an accepting surviving clearing member after the original member defaults. The model states the authority and funding premises needed for these actions.

1.4 Relation to the literature

A copula describes the dependence between random outcomes after their individual distributions have been fixed. Loss-versus-rebalancing compares a pool’s value with a strategy that continuously holds the same instantaneous quantities at the external market price. The literature below supplies these comparisons and the institutional framework.

CCP risk management.

The applied CCP-risk literature decomposes into four strands. On margin methodology and cross-margin efficiency, Cont and Kokholm [42] analyse multilateral versus bilateral netting in a multi-CCP setting; their margin-efficiency theorem is the benchmark for Proposition 3.6 and Proposition 3.14. Cruz Lopez, Harris, Hurlin, and Pérignon [45] develop CoMargin for correlation-aware initial margin, a direct counterpart of the parametric ES aggregation of (2). Ghamami and Glasserman [46] characterise initial-margin efficiency under stressed versus non-stressed regimes.

On default-fund sizing, skin-in-the-game, and waterfall design, Duffie and Zhu [43] give the foundational comparison of bilateral and centrally-cleared counterparty risk; Murphy [44] develops the canonical Cover-1 and Cover-2 default-fund sizing rules and the skin-in-the-game tranche between defaulter margin and mutualisation; Biais, Heider, and Hoerova [47] analyse incentive alignment between the CCP and its clearing members.

The regulatory sources are the CPMI-IOSCO Principles for Financial Market Infrastructures [48] (Principle 4 on credit risk and Principle 7 on liquidity risk), EMIR Articles 42–45 [49, 50] (default-fund and dedicated-resource sizing, liquidity controls, and the default-management waterfall), and Dodd-Frank Title VIII [52] (U.S. Financial Market Utility designation and risk-management standards).

Earlier theoretical treatments by Acharya and Bisin [5] and Pirrong [6] motivate the central-clearing arrangement. The SPAN family [7] is the industry benchmark for scenario margining. We take it as the reference for our AMM-kernel specialisation.

The positioning of §6 against this literature is as follows. Theorem 6.12 is not an Eisenberg-Noe fixed point: in Eisenberg-Noe [1, 2] each node’s payment depends on the payments it receives and the clearing vector is the fixed point of that map, whereas here the losses entering the waterfall are fixed at clearing time and the waterfall is a deterministic allocation whose only non-trivial step is the capped pro-rata socialisation.

Socialisation debits surviving members’ collateral; auto-deleveraging extinguishes profit claims rather than debt. Definition 6.8 follows the EMIR Art. 45 order through the socialisation stage, with the skin-in-the-game tranche of Definition 6.1 between defaulter seizure and fund draw; the auto-deleveraging stage has no EMIR counterpart.

Definition 6.2 implements joint-scenario credit prefunding, with the regime distinctions in Remark 6.4. Porting of client positions (EMIR Art. 48; PFMI Principles 13 and 14) receives the treatment of §6.5, where the AMM structure makes a client position a pool-share claim that can be transferred granularly across surviving counterparties, altering the porting-versus-liquidation trade-off.

AMM risk and LP economics.

The AMM-risk literature characterises LP exposure in two complementary ways. Angeris, Kao, Chiang, Noyes, and Chitra [13] analyse Uniswap-style constant-product markets and introduce the arbitrage-equilibrium argument underlying deterministic price impact. Evans, Angeris, and Chitra [53] derive optimal fees for geometric-mean market makers, compensating LPs for the expected loss against a rebalancing benchmark.

Milionis, Moallemi, Roughgarden, and Zhang [54] introduce loss-versus-rebalancing (LVR), a continuous-time baseline for LP losses that equals \sigma^2/8 per unit time per unit LP value in the constant-product setting and generalises to the g_i-weighted family through the weighted Black-Scholes replication of the trade-free LP payoff.

Theorem 8.8 in §8 places these results in the waterfall: the recovery shortfall of a liquidation is borne by the defaulter’s estate as a reduction of Stage-1 recovery, while LPs bear the divergence loss of the trade, net of fees, and only while the price move persists. Section 3 also integrates LVR as a margin input when pool-share positions serve as collateral.

Network clearing and fire-sale contagion.

The network-clearing literature begins with Eisenberg-Noe [1] and has been extended to include bankruptcy costs [2], fire-sale externalities [3], and indirect contagion [4]. Allen and Gale [55] develop the correlated-failure account of financial contagion that underlies the correlated-depeg residual of Corollary 11.8. Theorem 8.4 combines the exact AMM mark kernel with stated holdings and funding-response rules to bound cumulative liquidation.

Reflexivity and impasse classification.

The reflexivity and death-spiral analysis of algorithmic stablecoins [14, 16, 15, 17] is qualitative. The dynamical object we identify is classical. The coupled price-liquidity system is a constrained system A(x)\dot x = F(x); its critical locus \Sigma = \{\det A = 0\} is an impasse surface in the sense of Takens [24] and Riaza [25]; finite-time blow-up of |\dot P_M| on approach is the classical impasse phenomenon; and the time rescaling of §10 is the standard desingularization.

Points where the equilibrium set meets \Sigma are equilibrium–impasse intersections at which a singularity-induced bifurcation can occur in the sense of Venkatasubramanian, Schättler, and Zaborszky [26]; a particular parameterised passage requires transversality and non-degeneracy conditions not assumed here.

Our contribution applies that classification to this economic system. The coefficient \varrho separates the LP and clearing-layer components, locates the critical threshold, rules out a fold, and supports the finite-time collapse result on the invariant branch. The classification determines the policy conclusion: a Sotomayor fold would imply a structurally stable two-equilibrium picture near the threshold, whereas the impasse classification says the scalar reduction has no continuous extension across \Sigma and the reduced model is silent beyond it. The singular-perturbation apparatus [18, 19, 20, 21, 22, 23] enters only through the regularised system of Open Problem 5.

1.5 Organization

The argument begins with the loss entering clearing. Sections 25 specify the reserve model, portfolio losses, probability laws, numerical allowances, and continuing model checks. These inputs determine required margin and its retained level when a model fails. Section 6 then fixes the funded account state and allocates losses through the waterfall. It also separates that allocation from legally final settlement and compares accepted transfers with liquidation. Section 7 handles changes in the permitted trading book.

Liquidation can change the next loss calculation. Section 8 bounds that effect through explicit holdings and funding responses. Sections 910 introduce the separate model in which withdrawals change the hub asset’s value. Section 11 identifies the settlement discipline that removes its clearing-induced withdrawal channel and evaluates the funded buyback conditions. Section 12 treats losses in the settlement assets themselves. Section 13 states the adversarial bounds under specified strategies. Section 14 evaluates the loss, detection, and funded-execution calculations under declared generators. Section 15 records the remaining problems.

The appendices carry the calculations needed to use those results. Appendix A evaluates the restricted cross-margin formula. Appendix B follows a loss through the appropriate clearing book. Appendix C answers the remaining timing question from the opening example. Its backward recursion computes the exact cash needed to complete a finite plan after every represented observation. The settlement-record argument then explains how that cash condition survives committed payments, repeated reports, and returns under its stated provider and storage assumptions.

2 Setup and Assumption Model

2.1 The AMM-CCP market model

We fix the following structure. A central counterparty clears trades for N spoke pools. Each pool trades a spoke asset B_i against a common hub asset M. Pool i has reserves (R_{\!M}^{(i)}, R_{\!B}^{(i)}).

Its constant-function invariant is R_{\!M}^{(i)} \cdot (R_{\!B}^{(i)})^{g_i} = k_i with coupling exponent g_i>0. The case g_i=1 recovers constant-product markets [12, 13]. Every positive exponent defines a power-weighted market, with marginal price P_i=g_iR_{\!M}^{(i)}/R_{\!B}^{(i)}.

The reserve rule fixes how a sale changes both pool balances. Its constant k_i stays fixed within an execution window, while the positive exponent g_i determines the shape of the price response. The marginal price is the price of an additional infinitesimal unit. The average price uses the total proceeds of the actual sale. We distinguish them because collateral recovery uses proceeds and unsold holdings use the recorded accounting price.

Notation.

Throughout, P_M > 0 denotes the price of a hub asset M; L \geq 0 denotes aggregate locked liquidity across N spoke pools; f: \mathbb{R}_{\geq 0} \to \mathbb{R}_{\geq 0} is a C^1 increasing concave function with f(0) = 0 (the endogenous value function); \bar V > 0 is the exogenous mean-reversion target; \theta > 0 is the exogenous mean-reversion rate; \lambda > 0 is the dimensionless LP withdrawal elasticity of Definition 9.1; \Gamma \geq 1 is the dimensionless liquidation-leverage factor of Definition 9.2. Reserves of pool i are (R_{\!M}^{(i)}, R_{\!B}^{(i)}); \pi \in [0,1] denotes an event-outcome probability; \mathop{\mathrm{ES}}_q is Expected Shortfall over the worst q probability mass, and liquidation volumes are written Q_i.

Assumption 2.1 (Pricing and impact model).

  1. (AMM invariant.) Each pool satisfies R_{\!M}^{(i)} (R_{\!B}^{(i)})^{g_i} = k_i with g_i>0 and k_i>0. The exponent stays fixed during each execution window. A parameter update starts a new window from the actual reserves and records its new invariant constant.

  2. (Deterministic price impact.) Selling Q > 0 units of B_i into pool i yields hub proceeds \Delta_M(Q; i) = k_i [(R_{\!B}^{(i)})^{-g_i} - (R_{\!B}^{(i)} + Q)^{-g_i}] and post-trade pool reserves (R_{\!M}^{(i)} - \Delta_M(Q;i),\; R_{\!B}^{(i)} + Q). This is exact and known to the clearinghouse.

  3. (Linear-in-log return model.) Over a short horizon, spoke-asset log-returns are centred and standardised and admit r_i=\beta_iF+\varepsilon_i. The common factor F has unit variance. The residuals are centred, mutually uncorrelated, and uncorrelated with F, with \operatorname{Var}(\varepsilon_i)=1-\beta_i^2 and |\beta_i|\leq1. Exact quadratic ES aggregation additionally requires the centered joint elliptical projection law in Proposition 3.2. Covariance assumptions alone do not impose that law. Full nonlinear AMM and event losses remain inputs to the scenario and physical-risk engines.

Remark 2.2 (Signed signals and the execution domain).

For a bounded signal h with |h|\leq d and sensitivity \alpha>0, the map g=\exp(\alpha h) has image [e^{-\alpha d},e^{\alpha d}]. A negative signal therefore gives a positive exponent below one and retains a nonzero price response. The execution bounds in Proposition 8.1, the LVR identity in Proposition 3.23, and Theorem 8.8 cover this entire image. The fire-sale bound uses the actual diagonal entries g_i+1 in Theorem 8.4. Each result retains its stated price, holdings, horizon, and fee assumptions.

An exponent update preserves the observed reserve quantities and changes k_i to R_{\!M}^{(i)}(R_{\!B}^{(i)})^{g_i}. It can change marked value and the cost of a subsequent trade. Execution across several updates follows the resulting reserve sequence, including actual fee deposits. The fixed-window bounds apply to its separate legs. A claim about the whole sequence additionally requires the funded execution policy of the coupling mechanism.

A portfolio’s profit and loss, abbreviated P&L or written \mathrm{PnL}, includes every admitted position in the same scenario. A stress scenario specifies a joint market outcome used to evaluate that loss. The following policy selects the tail measure and the order in which funded resources and eligible claims absorb a realized shortfall.

Assumption 2.3 (Clearinghouse policy).

  1. (Margin measure.) The clearinghouse uses scenario-based Expected Shortfall over the worst q\in(0,0.01] probability mass. The portfolio P&L function sums spot, derivative, and event-linked instrument P&L within each stress scenario.

  2. (Insurance fund.) An insurance fund \mathrm{IF} \geq 0 is held in a specified settlement asset (§11 treats the endogenous and exogenous cases separately).

  3. (Waterfall.) On a default event with positive gross loss, the clearinghouse executes the generalized waterfall of §6.2: (1) defaulter margin seizure, (2) optional CCP skin-in-the-game layer (Definition 6.1), (3) insurance-fund draw (sized per Definition 6.2), (4) capped socialisation with per-position cap \kappa \in (0, 1), (5) auto-deleveraging (ADL) of profitable counterparties. The skinless case E_{\mathrm{SIG}}=0 collapses this to a four-stage operational waterfall.

The valuation assumption below applies only to the later price-withdrawal dynamics. It separates a component independent of pool liquidity from a component that increases with liquidity. The initial nonnegativity condition constrains the starting state. For the levered dynamics, the subsequent price equation determines whether that decomposition remains nonnegative.

Assumption 2.4 (Endogenous-value structure (used only in §§9-11)).

The hub asset’s price decomposes as P_M(t) = V_{\mathrm{ext}}(t) + V_{\mathrm{end}}(t) where:

  • V_{\mathrm{ext}} is exogenous, mean-reverts at rate \theta > 0 to \bar V > 0 independently of L, and is non-negative at the initial state: V_{\mathrm{ext}}(0) \geq 0, equivalently f(L_0) \leq P_{M,0};

  • V_{\mathrm{end}} = f(L) with f C^1, strictly increasing, concave, f(0) = 0. Canonical: f(L) = \beta_L L^\gamma with \gamma \in (0, 1].

Whether the decomposition is preserved in time depends on the clearing layer. When no clearing action withdraws locked liquidity (the unlevered case \Gamma = 1 of Definition 9.2), V_{\mathrm{ext}} obeys \dot V_{\mathrm{ext}} = \theta(\bar V - V_{\mathrm{ext}}) exactly and stays non-negative, so f(L) \leq P_M at every time along the trajectory. When clearing-layer liquidations withdraw liquidity (\Gamma > 1), the price equation (50) is the primitive dynamics and V_{\mathrm{ext}} := P_M - f(L) is a derived quantity that the dynamics do not keep non-negative; Theorem 9.7 says where it crosses zero. Under the settlement discipline of Definition 11.1 the clearing layer is unlevered, which is the content of Theorem 11.2.

Remark 2.5 (Scope of the model).

Assumption 2.1 specifies the AMM kernel; Assumption 2.3 specifies CCP policy; Assumption 2.4 enters only when we study the reflexive channel. Results that do not invoke Assumption 2.4 (all of §§3-8) hold regardless of hub-asset valuation structure.

3 Portfolio Margin under the AMM Kernel

We develop the portfolio-margin method that the CCP uses to compute required capital. The architecture adapts CME-SPAN scenario margining [7].

It also adapts parametric Expected Shortfall aggregation [8] to the AMM-price-impact kernel.

Definition 3.13 uses correlation credits that correspond to SPAN inter-spread credits. SPAN is the benchmark in the sense of Cont-Kokholm [42].

3.1 Scenario-based Expected Shortfall

A scenario distribution assigns a probability to each specified market outcome. The margin calculation applies the actual portfolio loss map in each outcome, then averages its worst tail. Offsets between positions therefore enter through their joint losses.

Definition 3.1 (Portfolio margin).

Let \Pi be a portfolio and \{(\omega_s,p_s)\}_{s=1}^S a finite stress distribution, where p_s\geq0, \sum_sp_s=1, and each scenario specifies price shocks and event-outcome shifts. The portfolio margin is M(\Pi) := \mathop{\mathrm{ES}}_q\!\left(-\mathrm{PnL}(\Pi,\omega);\{p_s\}_{s=1}^S\right)\cdot(1+\zeta), \tag{1} where q\in(0,0.01] is the tail probability, \zeta\geq0 is a design buffer (values in [0.10,0.25] are representative of CCP add-on practice; no calibration is derived here), and \mathrm{PnL}(\Pi,\omega) is computed using the AMM kernel of Assumption 2.1. A first-order stochastic increase in the loss distribution raises \mathop{\mathrm{ES}}_q and therefore raises M(\Pi).

A quadratic formula can replace this scenario calculation only under additional distributional assumptions. A centered return has mean zero. An elliptical joint law gives every linear portfolio the same standardized distribution, with a direction-dependent scale. The next result makes this common projection property explicit, so its scope excludes an arbitrary portfolio of nonlinear payoffs. Here a covariance matrix records variances and pairwise co-movements, while its normalized correlation matrix has unit diagonal.

Proposition 3.2 (Exact centered elliptical linear-loss aggregation).

Fix one horizon and one centered jointly elliptical return vector r with finite covariance \boldsymbol\Sigma=D\mathbf P D, where D=\mathop{\mathrm{diag}}(\sigma_i) and \sigma_i>0. Its standardized scalar projection Z has the same law in every nonzero direction: a^\top r\overset d=\sqrt{a^\top\boldsymbol\Sigma a}\,Z. Let k_q=\mathop{\mathrm{ES}}_q(Z) and use a common buffer \zeta. For centered linear loss L_0=a^\top r, define signed standalone amounts m_i=(1+\zeta)k_q a_i\sigma_i. The exact linear charge is M^{\mathrm{lin}}(\Pi)^2=\mathbf m^\top\mathbf P\mathbf m, \qquad M^{\mathrm{lin}}(\Pi)=(1+\zeta)k_q\sqrt{a^\top\boldsymbol\Sigma a}. \tag{2} For loss d+a^\top r, the nonnegative requirement is (1+\zeta)[d+k_q\sqrt{a^\top\boldsymbol\Sigma a}]_+. The constant loss d is separate from the centered scaling vector \mathbf m. Below, M^{\mathrm{port}} denotes this exact centered linear charge where the projection assumptions hold. Nonlinear and indicator-containing losses use their full loss maps or the certified approximation below.

Proof. Positive homogeneity and translation invariance of ES give the displayed scalar charge. Expanding \mathbf m=(1+\zeta)k_qDa gives the quadratic identity. A zero-variance centered projection is zero almost surely and has zero ES. The direction-independent projection law is an additional distributional premise. ◻

For a nonlinear payoff, write its loss as an approximating loss plus a remainder. The next bound turns a bound on the remainder’s expected absolute size into an additional tail-loss allowance. A common uncertainty set contains the alternative probability laws being considered for every portfolio.

Proposition 3.3 (Certified nonlinear-loss approximation).

Let L=L_0+R with L,L_0 integrable under every law in a fixed common uncertainty set \mathcal U. Suppose \varepsilon_R\geq\sup_{\nu\in\mathcal U}\mathbb{E}_\nu|R| and both robust ES suprema are finite. Then \left|\sup_{\nu\in\mathcal U}\mathop{\mathrm{ES}}_q^\nu(L) -\sup_{\nu\in\mathcal U}\mathop{\mathrm{ES}}_q^\nu(L_0)\right| \leq\varepsilon_R/q. Thus (1+\zeta)[\sup_{\nu\in\mathcal U}\mathop{\mathrm{ES}}_q^\nu(L_0)+\varepsilon_R/q]_+ is a sufficient requirement before numerical allowances. The certificate supports any integrable approximation, including nonlinear claims on unbounded state spaces.

Proof. The coupling (L,L_0) has expected distance \mathbb{E}_\nu|R|. The threshold hinge in (21) is 1-Lipschitz, so the ES difference is at most that distance divided by q. Apply the bound in both directions and take suprema over the same \mathcal U. ◻

Remark 3.4 (Computing the remainder certificate).

A Hessian norm bound H on a recorded convex region gives |R|\leq H\|r\|^2/2 for the local affine Taylor approximation. The certificate separately includes \mathbb{E}(|R|\mathbf1_{\text{outside}}). A digital jump requires the jump-aware partition in Proposition 4.13. For a single integrable loss, finite conditional-expectation approximations can converge in L^1. Uniform approximation over selectable portfolios and \mathcal U requires a uniform certificate. For Gaussian Z, the loss Z^2-1 has zero derivative at zero but positive tail ES. The full loss engine retains this exposure even when its local linear term vanishes.

Some markets compute prices from a differentiable cost of issuing a portfolio. The Hessian is that cost’s matrix of second derivatives and describes local price sensitivity. For the following logarithmic cost, it also has an exact covariance interpretation under the pricing law. That interpretation does not by itself estimate the probabilities of realized future losses.

The weights w_j are positive reference weights on the payoff vectors v_j. At position x, the law Q_x assigns probabilities proportional to w_j\exp(v_j^\top x/b), normalized over j.

For a log-partition cost C_b(x)=b\log\sum_j w_j\exp(v_j^\top x/b), \nabla^2 C_b(x)=b^{-1}\mathop{\mathrm{Cov}}_{Q_x}(v). Here Q_x is the pricing law, v_j is a payoff vector, and b>0 is the liquidity parameter. This identity supplies a pricing covariance feature. Physical forecasting requires a specified map from observations and pricing features to a physical law, as in Definition 4.4. Outside the log-partition class, a Hessian describes local price impact and requires a separate statistical interpretation.

The clearing calculation adds losses, collateral, and numerical allowances. They must refer to the same time, obligations, and currency unit. A numeraire is that common valuation unit. A valuation certificate records the inputs and conversion assumptions used for the calculation.

Definition 3.5 (Units and valuation certificate).

Every calculation records one settlement numeraire, valuation time, position snapshot, and margin horizon with its time unit. It records asset quantities, conversion prices, eligible conversion routes, costs, haircuts, and legal encumbrances. Each loss, margin, drawable balance, and error allowance is an amount in that numeraire. Different settlement assets require recorded conversion into that common unit before addition. For C_b, position x_i has units of contracts, payoff v_i has currency per contract, and b has currency units. Thus (\nabla^2 C_b)_{ij} has currency per contract squared. Normalising its entries by positive diagonal square roots gives a dimensionless pricing correlation. It does not identify physical return correlation. The certificate records the return transformation and horizon used to estimate physical correlations. The quantities q, \zeta, and correlation coefficients are dimensionless. The loss-law Wasserstein radius \eta and numerical allowance \varepsilon in Proposition 4.5 have currency units. A radius for dimensionless state returns requires a loss-map Lipschitz constant before it can bound monetary loss.

The factor model attributes part of every return to one common random driver and the rest to its own residual. Under equicorrelation, all distinct pairs have the same correlation. This special case gives a sharp comparison between summed standalone margins and the joint charge. The counterexample in the proposition explains why averaging unequal correlations does not preserve that bound.

Proposition 3.6 (Portfolio margin under the factor model; equicorrelation efficiency bound).

Under the factor decomposition r_i = \beta_i F + \varepsilon_i of Assumption 2.1(3) and standalone margins m_i > 0, the portfolio margin satisfies M^{\mathrm{port}}(\Pi)^2 \;=\; \Bigl(\textstyle\sum_i m_i \beta_i\Bigr)^{\!2} + \sum_i m_i^2 (1 - \beta_i^2). \tag{3} Under equicorrelation, \rho_{ij} = \bar\rho \in [0, 1] for all i \neq j (the factor model with equal loadings, \bar\rho = \beta^2), the efficiency ratio \eta(\Pi) := \sum_i m_i / M^{\mathrm{port}}(\Pi) satisfies \eta(\Pi) \;\leq\; \sqrt{\frac{N}{1 + (N-1)\bar\rho}} \tag{4} for every positive margin vector. If \bar\rho<1, equality holds exactly when all m_i are equal. If \bar\rho=1, every positive margin vector attains equality and \eta=1. The bound is specific to equicorrelation: under a general factor model with unequal loadings it can fail (loadings (0.9, 0.9, 0.1) and margins (0.5, 0.5, 1) give \eta^2 = 1.92 against 3/(1 + 2\bar\rho) = 1.81 at the average correlation \bar\rho = 0.33).

Proof. Formula (3) is the quadratic form \mathbf{m}^\top(\boldsymbol\beta\boldsymbol\beta^\top + \mathbf{D})\mathbf{m} for the factor-model correlation matrix \mathbf{P} = \boldsymbol\beta\boldsymbol\beta^\top + \mathop{\mathrm{diag}}(1 - \beta_i^2), which is positive semidefinite by construction. Under equicorrelation, M^{\mathrm{port}}(\Pi)^2 = (1 - \bar\rho)\sum_i m_i^2 + \bar\rho\,(\sum_i m_i)^2 \geq (\sum_i m_i)^2\,[(1 - \bar\rho)/N + \bar\rho] by Cauchy-Schwarz, \sum_i m_i^2 \geq (\sum_i m_i)^2/N, with equality exactly when the m_i are equal. This equality condition passes to the margin bound when 1-\bar\rho>0. At \bar\rho=1, that coefficient vanishes and M^{\mathrm{port}}=\sum_i m_i for every positive vector. Rearranging gives (4). The counterexample is a direct evaluation of (3). ◻

Corollary 3.7 (Asymptotic ceiling).

Under equicorrelation, as N \to \infty with \bar\rho > 0 fixed, \limsup_N \eta \leq 1/\sqrt{\bar\rho}, and the equal-margin portfolios, which attain (4) at every N, converge to that ceiling: portfolio margin provides a constant-factor capital saving, not an asymptotically growing one. An unequal margin sequence need not approach the ceiling (m_1 = 1 and m_i = 1/N for i \geq 2 give \eta \to 2/\sqrt{1 + 3\bar\rho}). At \bar\rho = 0.2 the ceiling is 1/\sqrt{0.2} \approx 2.24, so portfolio margin at best roughly halves the capital requirement.

3.2 Within-venue effective depth

The same quadratic layer determines how much additional notional the margin system can support. This is effective balance-sheet depth, not displayed AMM reserve depth.

Remark 3.8 (Depth, netting, and settlement funding).

Displayed AMM depth is the reserve quantity quoted at the venue. Effective margin depth is the additional notional that the CCP can admit under its margin formula. Settlement funding is the settlement asset due on the funding clock after permitted netting. These quantities are not interchangeable.

The reported magnitudes show the distinction. CLS reported settlement in 18 currencies and average daily settled value of USD 7.9 trillion in the first half of 2025. Multilateral netting reduced required funding to about 4 percent of gross value. Its in/out swaps reduced funding further, to about 1 percent [29, 30]. CHIPS reported a 26:1 liquidity-efficiency ratio in 2025 and average daily payment value of USD 2.014 trillion [31, 32]. NSCC reported a 98.6 percent netting rate and USD 3.01 trillion in average daily value for 2025 [33]. Our arithmetic gives a post-netting residual of about USD 42.1 billion: 3.01\ \text{trillion}\times(1-0.986) =0.04214\ \text{trillion}. These institutional reports describe funding reductions. They are not inputs to the solvency theorem below.

Fix the current portfolio and a further amount of free margin. The question is how much of one additional position the covariance charge permits. The quantity b_i(\mathbf q) below measures how that position co-moves with the existing book. The proof solves the resulting quadratic inequality and bounds its cross term by Cauchy–Schwarz.

Proposition 3.9 (Effective depth and its sharp diversification bound).

Let \boldsymbol\Sigma\succeq0 be a covariance matrix with \Sigma_{ii}=\sigma_i^2>0, let R(\mathbf q):=\sqrt{\mathbf q^\top\boldsymbol\Sigma\mathbf q}, and let b_i(\mathbf q):=\mathbf e_i^\top\boldsymbol\Sigma\mathbf q. With free margin F>0, define L_i^{\mathrm{eff}}(\mathbf q,F) :=\sup\{x\geq0:R(\mathbf q+x\mathbf e_i)\leq R(\mathbf q)+F\}. Then L_i^{\mathrm{eff}}(\mathbf q,F) =\frac{-b_i(\mathbf q)+\sqrt{b_i(\mathbf q)^2+\sigma_i^2\{2R(\mathbf q)F+F^2\}}}{\sigma_i^2}. \tag{5} Relative to the isolated depth F/\sigma_i, the bonus is strict exactly when b_i(\mathbf q)<\sigma_iR(\mathbf q). Moreover \frac{F}{\sigma_i}\leq L_i^{\mathrm{eff}}(\mathbf q,F)\leq\frac{2R(\mathbf q)+F}{\sigma_i}. The lower equality holds at b_i=\sigma_iR and the upper equality at b_i=-\sigma_iR.

Proof. Squaring the defining inequality gives \sigma_i^2x^2+2b_i(\mathbf q)x-\{2R(\mathbf q)F+F^2\}\leq0, whose positive root is (5). Cauchy–Schwarz in the \boldsymbol\Sigma seminorm gives |b_i|\leq\sigma_iR. The root is strictly decreasing in b_i, because its derivative is \frac{-1+b_i/\sqrt{b_i^2+\sigma_i^2(2RF+F^2)}}{\sigma_i^2}<0. Substitution at the two endpoints b_i=\pm\sigma_iR gives the stated equalities and bounds. ◻

Corollary 3.10 (Aggregate notional in the full equicorrelation range).

Suppose n\geq2 markets have volatility \sigma>0, covariance \boldsymbol\Sigma_n(\rho)=\sigma^2\{(1-\rho)\mathbf I_n+\rho\mathbf1\mathbf1^\top\}, \qquad \rho\in\left(-\frac1{n-1},1\right], and total free margin nF. With V:=F/\sigma, the maximum long-only total notional is L(n,\rho)=nV\sqrt{\frac{n}{1+(n-1)\rho}}. \tag{6} For \rho\in[0,1], nV\leq L(n,\rho)\leq n^{3/2}V. Negative correlation can exceed that range. For example, L(n,-1/n)=n^2V. The expression diverges as \rho\downarrow-1/(n-1) because the covariance model becomes singular; that limit is not a capacity claim.

Proof. The feasible set and objective are permutation invariant and convex, so averaging a maximiser over coordinate permutations gives a symmetric maximiser \mathbf q=x\mathbf1. The binding constraint is \sigma x\sqrt{n\{1+(n-1)\rho\}}=nF, which gives (6). The remaining statements follow by substitution on the stated positive-semidefinite range. ◻

3.3 Valid correlation matrices and structural priors

Sample correlations converge slowly for new spoke markets [9]. CCPs mitigate this with structural priors (e.g., sector-based correlation matrices), blended with the sample estimate.

A positive-semidefinite matrix (PSD) gives a nonnegative variance for every portfolio. Choosing individually plausible pairwise correlations can violate that requirement. Shrinkage blends a sample estimate with a structural prior, meaning a matrix based on specified background relationships. The construction below first makes the prior a valid correlation matrix.

Remark 3.11 (PSD shrinkage).

Let \hat{\mathbf{P}} be a Pearson sample correlation matrix. Project a symmetric structural prior to a positive-definite matrix \widetilde{\mathbf P} by flooring its eigenvalues at \epsilon>0, then renormalise it to unit diagonal: \mathbf P^{\mathrm{prior},+}:=\mathbf D^{-1/2}\widetilde{\mathbf P}\mathbf D^{-1/2}, \qquad \mathbf D:=\mathop{\mathrm{diag}}(\widetilde{\mathbf P}). This renormalisation is necessary because eigenvalue flooring alone need not preserve a correlation matrix’s unit diagonal. For any w_s\in[0,1], the blend \mathbf P=(1-w_s)\hat{\mathbf P}+w_s\mathbf P^{\mathrm{prior},+} is a positive-semidefinite correlation matrix. A prior built from pairwise correlations need not be positive semidefinite: (\rho_{12},\rho_{13},\rho_{23})=(0.9,0.9,-0.9) has minimum eigenvalue approximately -0.80.

Definition 3.12 (Sign-aware PSD correlation stress set).

For a signed risk vector \mathbf m, let \mathcal P_{\mathrm{stress}}(\mathbf m) be a specified set of positive-semidefinite correlation matrices. The required parametric charge over this set is M_{\mathrm{corr}}(\mathbf m) := \sup_{\mathbf P\in\mathcal P_{\mathrm{stress}}(\mathbf m)} \sqrt{\mathbf m^\top\mathbf P\mathbf m}. The stress applies to the whole quadratic form. It does not replace each correlation entry by an independent extreme. For two opposite-signed legs, lower return correlation raises the charge. For two same-signed legs, higher return correlation raises it. Entrywise extrema can fail to form a positive-semidefinite matrix.

3.4 Cross-margining specification: spot, perpetual, and event positions

The portfolio margin framework above treats positions abstractly. In practice the clearinghouse cross-margins across three instrument types (spot, perpetual, and event-linked positions), each with distinct risk profile and hedging relationship to the spoke asset. All offsets below are inputs to one scenario-ES generator; they are not additive credits independent of a positive-semidefinite risk model.

A spot position holds the asset itself. A perpetual position is a derivative exposure without a fixed maturity, whose price can differ from the spot price. That difference is the basis, and its variation leaves risk in an otherwise offsetting pair. An event-linked position pays according to a specified outcome. Cross-margining computes their collateral requirement jointly. Each leg is one component of the combined position.

The basis statistic b_i parametrizes the estimated basis-loss law used in its Expected Shortfall term below. For the power coupling G(E)=E^{\varkappa}, the model supplies the scalar event statistic E, its domain, and the configured exponent \varkappa. The domain and boundary convention must make that real power defined. These are declared calibration inputs. No event-specific coupling or volatility-to-loss fit is estimated here.

Definition 3.13 (Unified cross-margin computation).

Let a portfolio \Pi contain spot positions \{(B_i, Q_i^s)\}, perpetual positions \{(B_i, Q_i^p)\}, and event-linked positions \{(E_j, S_j)\}. The isolated margin treats each position independently: m^{\mathrm{iso}} = \sum_{i} |Q_i^s| \cdot P_i \cdot \mu_i^s \;+\; \sum_{i} |Q_i^p| \cdot P_i \cdot \mu_i^p \;+\; \sum_{j} S_j \cdot \mu_j^E \tag{7} where \mu_i^s, \mu_i^p, \mu_j^E are the respective margin rates (design parameters; the values \mu_i^s = 0.10, \mu_i^p = 0.05, \mu_j^E = 1.0 are used in Appendix A). The candidate offset schedules and floor below are evaluated against one full-loss portfolio charge.

(i) Spot/perpetual hedge discount. When a trader holds offsetting spot and perpetual positions in the same spoke asset, the overlapping notional receives a basis-risk-adjusted margin discount: D^{sp}_i = d_{\mathrm{sp}}(b_i) \times \min(|Q_i^s| \cdot P_i,\; |Q_i^p| \cdot P_i) \times \mu_i^p \times \mathbf{1}[\mathop{\mathrm{sgn}}(Q_i^s) \neq \mathop{\mathrm{sgn}}(Q_i^p)] \tag{8} where the indicator ensures the discount applies only to opposing directions (long spot / short perp, or vice versa), and the discount rate is a function of the observed basis volatility b_i: d_{\mathrm{sp}}(b_i) = \max\!\left(0.50,\;\; 1 - \frac{\mathop{\mathrm{ES}}_{q_b}[\,|P_i^{\mathrm{spot}} - P_i^{\mathrm{perp}}|\,]}{\mu_i^p \cdot P_i}\right), \qquad q_b:=0.005. \tag{9} The floor and the fallback discount applied when basis data are insufficient are design parameters.

Equation (9) selects the discount so that the retained margin covers the estimated basis ES. A static discount d combined with a realised basis loss b_q at upper (1-q) quantile leaves residual exposure L_{\mathrm{basis}}^{\max} = \bigl(b_q - (1 - d)\cdot \mu_i^p\bigr)_+ \times \mathcal{N}, \tag{10} with \mathcal{N} the per-instrument notional. Under (9) it vanishes whenever the floor of 0.50 is not binding; when the floor binds, the residual (b_q - 0.5\,\mu_i^p)_+ \times \mathcal{N} remains and is carried by the stress layer.

(ii) Event/spot correlation offset. Event-linked positions whose outcome correlates with spoke asset i’s spot price (through a coupling G(E) = E^{\varkappa}) earn a margin offset, set here to a design value of 40\% of the lesser notional: D^{pE}_i = 0.40 \times \min(|Q_i^s| \cdot P_i,\; S_i) \times \mu_i^s, \tag{11} where S_i is the event-linked stake on spoke asset i’s outcomes. The coefficient 0.40 is an admissible cap on one covariance term, not an additional discount if the same risk vector was already credited by the spot/perpetual hedge.

(iii) Margin floor. To prevent zero-margin portfolios even under perfect hedges, a floor at a design fraction (5\%) of isolated margin applies: m^{\mathrm{floor}} = 0.05 \times m^{\mathrm{iso}}. \tag{12}

Let m_i^{\mathrm{iso}} collect the terms of (7) on spoke i and its event-linked outcomes, so that \sum_i m_i^{\mathrm{iso}} = m^{\mathrm{iso}}, and let m_i^{(1)} := m_i^{\mathrm{iso}} - D_i^{\mathrm{hedge}} be the post-hedge margin of spoke i, where 0 \leq D_i^{\mathrm{hedge}} \leq \min\{m_i^{\mathrm{iso}},D_i^{sp}+D_i^{pE}\} is the within-spoke hedge credit, each covariance term counted once. Let R_{\mathrm{full}}(\Pi) be the certified full-loss charge from the scenario engine or the common physical uncertainty set. It includes the nonlinear-remainder and numerical allowances actually used. Its total credit and additional charge are D^{\mathrm{gen}}=(m^{\mathrm{iso}}-R_{\mathrm{full}})_+, \qquad A^{\mathrm{gen}}=(R_{\mathrm{full}}-m^{\mathrm{iso}})_+. Then R_{\mathrm{full}}=m^{\mathrm{iso}}-D^{\mathrm{gen}}+A^{\mathrm{gen}}. Each risk factor enters the full loss map once. The within-spoke schedules allocate candidate credits without reducing the resulting full-loss charge. The general cross-margin is m^{\mathrm{cross}}=\max\{R_{\mathrm{full}}(\Pi),m^{\mathrm{floor}}\}. \tag{13}

For the centered linear branch, each admitted physical law \nu requires the projection and scaling certificate of Proposition 3.2. Let \mathbf m(\nu) and \mathbf P(\nu) be its certified spoke scales and correlation matrix. With zero remainder and numerical allowances, the full robust charge is R_{\mathrm{full}}=\sup_{\nu\in\mathcal U} \sqrt{\mathbf m(\nu)^\top\mathbf P(\nu)\mathbf m(\nu)}. A single-form specialization requires this entire supremum to equal the stated quadratic charge. Its post-hedge amounts m_i^{(1)} must equal that form’s certified spoke scales. For example, a certified maximizing law supplies such a form. Under those additional conditions, R_{\mathrm{full}}=M^{\mathrm{port}}(\mathbf m^{(1)}) and \begin{aligned} D^{\mathrm{PSD}}(\Pi)&=\sum_iD_i^{\mathrm{hedge}}+D^{\mathrm{div}}(\Pi),\\ D^{\mathrm{div}}(\Pi)&=\sum_im_i^{(1)}-M^{\mathrm{port}}(\mathbf m^{(1)})\geq0. \end{aligned} \tag{14} The nonnegative post-hedge scales and a correlation matrix with entries at most one give the last inequality. This PSD identity describes that certified linear branch. A full digital or nonlinear scenario charge need not equal its square-root expression. For example, two independent losses 100\operatorname{Bernoulli}(0.005) have standalone \mathop{\mathrm{ES}}_{0.01}=50 each. Their total loss has exact \mathop{\mathrm{ES}}_{0.01}=100, while a zero-correlation quadratic aggregation of those standalone amounts gives 50\sqrt2. The full-loss engine computes the former value.

The general definition retains the full scenario loss charge. The next formula evaluates its certified linear special case, with equal exposure across spokes and an inactive minimum floor. It separates the saving from within-spoke hedges from the saving due to diversification across spokes.

Proposition 3.14 (Capital efficiency of cross-margining).

Under the certified centered linear branch of Definition 3.13 and Proposition 3.2, for a balanced portfolio (equal per-spoke notional across spot, perpetual, and event positions, the within-spoke hedge credit taken in full) over N_{\mathrm{br}} spoke-asset clusters, the capital-reduction ratio admits the closed form \begin{aligned} \frac{m^{\mathrm{cross}}}{m^{\mathrm{iso}}} &= \frac{m^{(1)}}{m^{\mathrm{iso}}_{\mathrm{per\,spoke}}} \sqrt{\bar\rho_{\mathrm{eff}}+\frac{1-\bar\rho_{\mathrm{eff}}}{N_{\mathrm{br}}}},\\ m^{(1)} &:=m^{\mathrm{iso}}_{\mathrm{per\,spoke}}-D^{sp}-D^{pE}, \end{aligned} \tag{15} whenever the floor (12) is non-binding. Here \bar\rho_{\mathrm{eff}}\in[0,1] is the equicorrelation of the scenario being evaluated. The formula applies per admissible equicorrelation scenario with its own certified spoke scales. The robust charge takes their supremum before applying the floor. A maximum exists when a maximizing scenario is certified. General positive-semidefinite scenarios use their full quadratic forms. Because the post-hedge spoke margins in this balanced submodel are non-negative, increasing \bar\rho_{\mathrm{eff}} is conservative here. That direction does not extend to signed hedge books. The ratio is the product of the within-spoke hedge factor m^{(1)}/m^{\mathrm{iso}}_{\mathrm{per\,spoke}} and the cross-spoke diversification factor \sqrt{\bar\rho_{\mathrm{eff}} + (1 - \bar\rho_{\mathrm{eff}})/N_{\mathrm{br}}}. It is monotone decreasing in each of the hedge-offset rates (D^{sp}, D^{pE}) and in N_{\mathrm{br}}, falling from the hedge factor at N_{\mathrm{br}} = 1 to \sqrt{\bar\rho_{\mathrm{eff}}} times it as N_{\mathrm{br}} \to \infty, and monotone increasing in \bar\rho_{\mathrm{eff}}. The expression requires certified common-family projection scales, exact credited hedge amounts, equal per-spoke notionals, and a non-binding floor. Uncertainty that changes the certified scales remains in that supremum. A positive nonlinear-remainder allowance remains in R_{\mathrm{full}} and changes the resulting ratio.

Proof. With per-instrument notional \mathcal{N} and rates (\mu^s, \mu^p, \mu^E), the per-spoke isolated margin is m^{\mathrm{iso}}_{\mathrm{per\,spoke}} = \mathcal{N}(\mu^s + \mu^p + \mu^E) and the post-hedge margin of every spoke is m^{(1)} = m^{\mathrm{iso}}_{\mathrm{per\,spoke}} - D^{sp} - D^{pE} by (8)-(11). The isolated total is N_{\mathrm{br}} \cdot m^{\mathrm{iso}}_{\mathrm{per\,spoke}}. Under equicorrelation \bar\rho_{\mathrm{eff}} with equal post-hedge margins m^{(1)}, Proposition 3.6 yields M^{\mathrm{port}}(\mathbf{m}^{(1)}) = m^{(1)}\sqrt{N_{\mathrm{br}}(1 + (N_{\mathrm{br}}-1)\bar\rho_{\mathrm{eff}})}, which by (14)-(13) is m^{\mathrm{cross}} when the floor is non-binding, and (15) follows. Monotonicity in \bar\rho_{\mathrm{eff}} is immediate from the square root; the derivative of \bar\rho_{\mathrm{eff}} + (1 - \bar\rho_{\mathrm{eff}})/N_{\mathrm{br}} in N_{\mathrm{br}} is -(1 - \bar\rho_{\mathrm{eff}})/N_{\mathrm{br}}^2 \leq 0, so the ratio decreases in N_{\mathrm{br}}, and its values at N_{\mathrm{br}} = 1 and as N_{\mathrm{br}} \to \infty are read off; monotonicity in (D^{sp}, D^{pE}) follows from the linear dependence of m^{(1)} on these variables. ◻

A pairwise discount can reuse the same hedge twice. The following three-position example shows why the joint charge must govern the total credit.

Proposition 3.15 (Pairwise credits can spend one hedge twice).

Let M(\mathbf q)=\sqrt{\mathbf q^\top\boldsymbol\Sigma\mathbf q} for one positive-semidefinite covariance matrix. The one-generator charge counts every covariance term once. Pairwise rebates calibrated on two-position sub-books need not dominate M. In particular, let \boldsymbol\Sigma= \begin{pmatrix} 1&-1/2&-1/2\\ -1/2&1&1\\ -1/2&1&1 \end{pmatrix}\succeq0, \qquad \mathbf q=(1,1,1)^\top. Then M(\mathbf q)=\sqrt3, equal to the root-sum-square isolated charge. Each of the sub-books (1,2) and (1,3) has charge 1 against isolated charge \sqrt2. Subtracting both pairwise credits therefore collects \sqrt3-2(\sqrt2-1)=2+\sqrt3-2\sqrt2\approx0.90<\sqrt3. The schedule collects about 52 percent of its own portfolio model’s charge.

Proof. The second and third rows of \boldsymbol\Sigma coincide, and the reduced two-factor correlation is -1/2, so \boldsymbol\Sigma is positive semidefinite. Direct evaluation gives \mathbf q^\top\boldsymbol\Sigma\mathbf q=3. Each named sub-book has variance 1+1-1=1, so each local credit is \sqrt2-1. Both credits use the first leg; subtracting them independently gives the displayed shortfall. ◻

Remark 3.16 (Whose balance sheet may recognise the saving).

The ratio above is a property of the margin system: it gives the collateral required by this venue. Regulatory capital relief is a separate legal consequence. It depends on the regulator’s recognition of the clearing house, its legal structure, its membership, and its default resources. The model follows the EMIR Article 45 order through the CCP-equity and mutualised stages, then adds auto-deleveraging (Assumption 2.3(3)). The ratio therefore measures venue margin and does not measure regulatory capital relief.

Remark 3.17 (Sensitivity formula, not a point estimate).

Equation (15) is a closed form in (N_{\mathrm{br}},\bar\rho_{\mathrm{eff}},D^{sp},D^{pE}) for its balanced, non-negative post-hedge margin vector. The paper’s formal content is the functional form and its monotonicities on that submodel; signed books use the PSD stress set of Definition 3.12. Representative evaluations appear in Appendix A.

Remark 3.18 (Design rationale for offset rates).

The spot-perp offset d_{\mathrm{sp}} is the complement of the basis-risk ES reserved by the margin system. The prediction-spot offset rate in (11) requires a calibration in which it lies below the regression beta of spot against event probability. That comparison is a design premise used to accommodate coupling-model misspecification. It requires a specified horizon, event signal, and fitted beta. This paper supplies no fitted beta establishing the comparison. The floor in (12) reserves capital against residual operational risks orthogonal to the hedge.

Remark 3.19 (Hedge-leg removal and re-margining).

The offset D^{sp}_i in (8) depends on the indicator \mathbf{1}[\mathop{\mathrm{sgn}}(Q_i^s) \neq \mathop{\mathrm{sgn}}(Q_i^p)]. If margin is recomputed only at block boundaries, an adversary can close one leg within a block and retain the discount until the next block. The AMM-deterministic price-impact kernel permits deterministic intra-block re-margining (Remark 13.13), making the indicator update synchronous with the leg removal and eliminating the exploit.

Remark 3.20 (Synthetic-directional decorrelation under events).

Portfolios constructed to appear hedged under the pre-event correlation estimate may decorrelate after the event, leaving the clearinghouse under-margined by (74). Charging the maximum of the portfolio margin over a stress set of positive-semidefinite correlation matrices that contains the post-event dependence (Remark 13.16) bounds the exposure. The stress is taken on the portfolio margin and not entry by entry: for a hedged pair the conservative direction is a lower return correlation, for a same-direction book a higher one, and the entrywise maximum of two correlation matrices need not be positive semidefinite. Forward-looking event-aware correlation updates reduce the remaining uncovered risk.

3.5 Fees, LP profit, and concentrated withdrawal

Additional positions permitted by margin rules can change volume and fees without adding reserves to a pool. The next calculation keeps three comparisons separate: fees per permitted notional, total provider profit, and reserves remaining after withdrawals.

Proposition 3.21 (Depth, profit, and withdrawal are separate quantities).

Margin aggregation changes effective depth, fee density, and LP profit through different equations. Let n identical markets have isolated effective depth V, baseline total volume U, fee rate f, and non-negative equicorrelation \rho. Write \Gamma_n(\rho):=\sqrt{\frac{n}{1+(n-1)\rho}}, the depth multiplier in Corollary 3.10. If aggregation changes volume to (1+\beta)U, fee flow per unit effective depth rises exactly when 1+\beta>\Gamma_n(\rho), \tag{16} because the isolated and aggregated ratios are fU/(nV) and f(1+\beta)U/(nV\Gamma_n).

Let c_0>0 be fixed operating cost per separate venue, c_1\geq0 per-market cost, and \Lambda_{\mathrm{iso}},\Lambda_{\mathrm{agg}} the respective non-fee risk costs. Then \Pi_{\mathrm{iso}}=fU-n(c_0+c_1)-\Lambda_{\mathrm{iso}}, \qquad \Pi_{\mathrm{agg}}=f(1+\beta)U-(c_0+nc_1)-\Lambda_{\mathrm{agg}}, so aggregation raises total LP profit exactly when f\beta U+(n-1)c_0>\Lambda_{\mathrm{agg}}-\Lambda_{\mathrm{iso}}. \tag{17} Conditions (16) and (17) are independent: deeper effective capacity can reduce fee flow per unit of depth while total LP profit rises.

For withdrawal stress, let displayed depth D=\sum_k\omega_kD with \sum_k\omega_k=1, let each LP withdraw at most a fraction g\in[0,1] in one stress window, and let a withdrawing coalition contain m LPs with \omega_k\leq\omega_{\max}. Then D^+\geq(1-gm\omega_{\max})_+D. \tag{18} When gm\omega_{\max}<1 and first-order impact is inverse in displayed depth, its inflation factor is at most (1-gm\omega_{\max})^{-1}. This is a displayed-depth bound. Effective margin depth is a joint function of the book and is not linearly attributable to LPs.

Proof. The two fee ratios give (16) by cancellation. Subtracting the two profit expressions gives (17). The coalition removes at most gD\sum_{k\in S}\omega_k\leq gm\omega_{\max}D in one window, proving (18); the impact ratio follows by division when the lower bound is positive. ◻

3.6 Impermanent loss and LVR as margin inputs

When LP pool-share positions serve as collateral at the CCP, they underperform a continuously rebalanced reference under ambient volatility at the loss-versus-rebalancing (LVR) rate of Milionis-Moallemi-Roughgarden-Zhang [54]. Liquidation events add discrete divergence loss. The margin computation of §3 must account for both relative losses and for the collateral’s absolute price path. Accepting pool shares as collateral is also the levered configuration of Definition 9.2: liquidating seized shares withdraws locked liquidity, which is the channel the settlement discipline of Definition 11.1 closes. This subsection describes a CCP that has chosen to carry that channel.

A pool share gives its owner a fraction of both reserve balances. Its absolute collateral value depends on the current reserve quantities and prices. The relative-performance calculations below compare that value with a specified benchmark, and each margin adjustment retains its own assumptions.

Definition 3.22 (LP-collateral process).

Let V^{\mathrm{LP}}_k(t) := \sum_i \alpha_{k,i}\bigl(R_{\!M}^{(i)}(t) + R_{\!B}^{(i)}(t)\cdot P_i(t)\bigr) be LP k’s pool-denominated collateral value at time t, where \alpha_{k,i} is k’s share of pool i. The collateral available to the CCP is C^{\mathrm{LP}}_k(t) = (1 - h_{\mathrm{LP}})\cdot V^{\mathrm{LP}}_k(t) where h_{\mathrm{LP}} \in [0, 1) is an LP-share haircut.

A continuous semimartingale permits both a drift and stochastic price fluctuations. Its quadratic variation measures the accumulated squared fluctuation used in the following loss rate. The result holds while the pool’s weights stay fixed and arbitrage keeps its price aligned with the external price.

Proposition 3.23 (LVR accrual on LP collateral).

Let the positive external price P_i be a continuous semimartingale with quadratic variation d\langle P_i\rangle_t=\sigma_i(t)^2P_i(t)^2\,dt. Assume a fixed-weight pool remains continuously aligned with this price by frictionless arbitrage. Use the self-financing strategy holding the pool’s instantaneous asset quantities as the rebalancing benchmark, with equal initial value. Fees, external flows, and parameter changes enter separate accounts. Let V^{\mathrm{LP}}_{k,i} := \alpha_{k,i}(R_{\!M}^{(i)} + R_{\!B}^{(i)} P_i) be the pool-i component of Definition 3.22. Where the conditional expectation is finite, the constant-product invariant (g_i = 1) gives the conditional LVR accrual rate \frac{\mathbb{E}[d\mathcal L^{\mathrm{LVR}}_{k,i}(t)\mid\mathcal F_t]}{dt} \;=\;\frac{\sigma_i^2}{8}\,V^{\mathrm{LP}}_{k,i}(t), \tag{19} where \mathcal L^{\mathrm{LVR}} is cumulative loss relative to the continuously rebalanced reference portfolio. For every fixed g_i>0, the conditional accrual rate is (\sigma_i^2/2)G(g_i)V^{\mathrm{LP}}_{k,i}(t) with G(g_i)=g_i/(1+g_i)^2. This gives G(1)=1/4 and the rate \sigma_i^2/8 at constant product. The result is a relative-performance drag, not an assertion that the LP token’s absolute value falls. Parameter changes contribute separate value increments.

Proof. The invariant R_{\!M}(R_{\!B})^{g_i} = k_i is a geometric-mean market with value weights 1/(1 + g_i) on the hub asset and w := g_i/(1 + g_i) on the spoke asset. For every g_i>0, these weights lie strictly between zero and one. The pool’s value in hub units is V = R_{\!M}+ P_i R_{\!B}= (1 + g_i)R_{\!M}, and along the invariant R_{\!M}\propto P_i^{w}, so V(P_i) \propto P_i^{w}. The LVR of a pool with value function V(P) against an exogenous-price rebalancer is (\sigma^2/2)\,P^2\,|V''(P)| per unit time [54], and P^2 |V''(P)| = w(1 - w)\,V(P) for V \propto P^w. Hence the rate is (\sigma_i^2/2)\, w(1 - w) = (\sigma_i^2/2)\, g_i/(1 + g_i)^2, which is \sigma_i^2/8 at g_i = 1. ◻

Corollary 3.24 (LVR reserve under a constant-coefficient relative-value model).

A CCP accepting LP collateral with margin horizon T_m must fund its expected underperformance against the rebalanced collateral benchmark. Write a:=(\sigma^2/2)G(g) and let \phi\in[0,1] be the fraction of required margin M(\Pi) assigned to LP shares. Assume the CCP uses the constant-coefficient relative-value model \dot{\bar V}^{\mathrm{LP}}=-a\bar V^{\mathrm{LP}} over the margin horizon, with all non-LVR benchmark moves handled elsewhere in the scenario margin. The initial collateral requirement is M^{\mathrm{LVR}}(\Pi) =M(\Pi)\bigl[1+\phi(e^{aT_m}-1)\bigr] =M(\Pi)\bigl[1+\phi aT_m+O(T_m^2)\bigr], \qquad a=\frac{\sigma^2}{8}\ \text{at }g=1, \tag{20} with a read as \max_i(\sigma_i^2/2)G(g_i) over the pools in which shares are held. The exponential is exact under the stated auxiliary relative-value model. It is not implied by the instantaneous LVR identity alone. At \phi=1 it reduces to e^{aT_m}M(\Pi). When LP shares are ineligible collateral, \phi=0 and the adjustment is zero.

Proof. The auxiliary model gives \bar V^{\mathrm{LP}}(T_m)=\bar V^{\mathrm{LP}}(0)e^{-aT_m}. Posting e^{aT_m}\phi M(\Pi) in LP shares therefore leaves relative benchmark value \phi M(\Pi) at the horizon. The remaining (1-\phi)M(\Pi) is not exposed to LVR. Adding the two initial components and expanding the exponential gives (20). ◻

3.7 Scope of the elliptical return model

The elliptical reduction also covers a common Student-t family with finite variance. This family allows heavier tails than a Gaussian law. The tail factor changes each charge, but cancels from the ratio when every linear projection uses the same family.

Corollary 3.25 (Common Student-t tail factor).

For the joint Student-t family with \nu>2, write Z=\sqrt{(\nu-2)/\nu}\,T_\nu so that \mathop{\mathrm{Var}}Z=1. Let t_{\nu,q} be the upper 1-q quantile and f_\nu its density. Then the common factor in Proposition 3.2 is k_{\nu,q}=\sqrt{\frac{\nu-2}{\nu}}\, \frac{\nu+t_{\nu,q}^2}{\nu-1}\, \frac{f_\nu(t_{\nu,q})}{q}. For a nonzero portfolio variance, the ratio of summed standalone centered ES to portfolio ES is \frac{\sum_i|a_i|\sigma_i}{\sqrt{a^\top\boldsymbol\Sigma a}}. The common tail factor and buffer cancel. The nonnegative equicorrelation bound in Proposition 3.6 therefore holds unchanged for every \nu>2.

Proof. Integrating x f_\nu(x) from t_{\nu,q} to infinity gives (\nu+t_{\nu,q}^2)f_\nu(t_{\nu,q})/(\nu-1). Multiply by the variance normalization and divide by q. Cancel the common positive factor in the standalone and portfolio charges. ◻

Remark 3.26 (Scope of the elliptical reduction).

The exact reduction requires one common centered joint elliptical family and linear losses. Different marginal tails, general copulas, and nonlinear payoffs require their own loss laws. Proposition 3.3 provides an explicit approximation allowance. Open Problem 10 concerns the broader dependence and nonlinear classes.

4 Continuous-Density Expected Shortfall

The scenario ES of Definition 3.1 uses a finite probability law. The same loss functional applies to continuous laws and laws with atoms. A clearing price law values payoffs. A physical forecast estimates realised losses over a specified horizon. This section defines ES for integrable losses, constructs a physical-risk requirement, and separates forecast uncertainty from numerical error.

4.1 Definition and tail-integral form

Definition 4.1 (Clearing price law).

At clearing time t, a probability measure Q_t on the outcome space \Omega is a clearing price law. For a Q_t-integrable payoff v, its price is \int v\,dQ_t. A density is one possible representation of this law. The following entropy-potential mechanism supplies an attained measure-valued clearing law under explicit feasibility assumptions. Physical margin continues to use Definition 4.4.

For a general law, several outcomes can have exactly the same loss at the tail threshold. Such a positive probability at one value is an atom. The formula below includes only the fraction needed to fill the worst tail mass. The auxiliary value v is a candidate loss threshold, and (x)_+ denotes the positive part of x.

Definition 4.2 (Continuous-density portfolio margin).

Let \mu_t be a probability law on a measurable outcome space \Omega. Let \ell_\Pi=-\mathrm{PnL}(\Pi,\cdot) be measurable, with \int|\ell_\Pi|\,d\mu_t<\infty. The Expected Shortfall over the worst q\in(0,1) probability mass is \begin{aligned} \mathrm{ES}_q^{\mu_t}[\Pi] &:=\inf_{v\in\mathbb{R}}\left\{v+\frac1q\int_\Omega(\ell_\Pi(\omega)-v)_+\,\mu_t(d\omega)\right\}\\ &=\frac1q\int_{\{\ell_\Pi>v_q\}}\ell_\Pi\,d\mu_t +\frac{q-\mu_t\{\ell_\Pi>v_q\}}q\,v_q, \end{aligned} \tag{21} the Rockafellar-Uryasev form, where v_q := \mathrm{VaR}_q^{\mu_t}[\Pi] := \inf\{v : \mu_t(\{\ell_\Pi \leq v\}) \geq 1 - q\} attains the infimum. When the loss law has no atom at v_q, \mu_t(\{\ell_\Pi = v_q\}) = 0, this is the tail integral q^{-1}\int_{\Omega_q(\Pi)} \ell_\Pi\, d\mu_t over \Omega_q(\Pi) := \{\omega \in \Omega : \ell_\Pi(\omega) \geq v_q\}; in general the second term takes only the fraction of an atom at the quantile that the q-tail contains, and integrating all of \{\ell_\Pi \geq v_q\} would overcount it. For the pricing-law instance, write Q_t for the measure in Definition 4.1. Then \mathop{\mathrm{ES}}_q^{Q_t} is a pricing diagnostic. Definition 4.4 specifies the physical-risk margin M^{\mathrm{cont}}.

Remark 4.3 (Well-posedness and coherence, after Acerbi-Tasche).

For an integrable loss, the infimum in (21) is finite and attained at a loss quantile. The loss may be unbounded. Moreover, \mathop{\mathrm{ES}}_q^{\mu_t}\ge\mathrm{VaR}_q^{\mu_t}. The Acerbi-Tasche coherence properties hold on integrable losses: subadditivity, monotonicity, translation invariance, and positive homogeneity [60].

A physical law describes how future outcomes occur, while a price law determines how payoffs are valued now. The symbol \mathcal F_t records the information available when the forecast is made. The common uncertainty set below represents the physical laws covered by the stated calibration evidence. Its transport-distance bound measures the expected monetary discrepancy between matched losses under two laws.

Definition 4.4 (Physical forecast and common uncertainty set).

Fix the margin horizon and a portfolio class before observing outcomes used to assess coverage. Let \mathcal F_t be the information available at calculation time. Let P_t denote the physical law for that horizon and \widehat P_t an \mathcal F_t-measurable forecast. The forecast may use recorded outcomes, current positions, and pricing-law features from Q_t. Let \mathcal U_t be a nonempty, \mathcal F_t-measurable set of physical laws containing \widehat P_t. Use the same set for every portfolio. For each admitted portfolio \Pi, require integrability under \widehat P_t and every \nu\in\mathcal U_t. Write \nu_\Pi=\nu\circ\ell_\Pi^{-1} for its scalar loss law. A loss-law certificate supplies a finite radius \eta_t(\Pi) such that W_1(\nu_\Pi,\widehat P_{t,\Pi})\le\eta_t(\Pi) \quad(\nu\in\mathcal U_t). Here W_1 is the infimum of \mathbb{E}|X-Y| over couplings of the two loss laws. Define R_t(\Pi):=\sup_{\nu\in\mathcal U_t}\mathop{\mathrm{ES}}_q^\nu[\Pi], \qquad M_t^{\mathrm{cont}}(\Pi):=(1+\zeta)[R_t(\Pi)]_+. The calibration certificate states the coverage event P_t\in\mathcal U_t and its claimed probability. It records the data cutoff, outcome identifiers, horizon, forecast, uncertainty-set constraints, tail assumptions, and portfolio selection rule. Adaptive portfolio selection requires coverage uniform over the selectable class or a valid conditional design. Numerical error and physical-law coverage are separate entries.

Proposition 4.5 (Physical Expected Shortfall certificate).

For integrable scalar loss laws P and \widehat P, W_1(P,\widehat P)\le\eta \quad\Longrightarrow\quad |\mathop{\mathrm{ES}}_q(P)-\mathop{\mathrm{ES}}_q(\widehat P)|\le\eta/q. Thus R_t(\Pi) in Definition 4.4 is finite. If a numerical value e_t(\Pi) satisfies |e_t(\Pi)-\mathop{\mathrm{ES}}_q^{\widehat P_t}[\Pi]|\le\varepsilon_t(\Pi), then R_t(\Pi)\le e_t(\Pi)+\varepsilon_t(\Pi)+\eta_t(\Pi)/q. On P_t\in\mathcal U_t, the same expression bounds physical ES. For a fixed common \mathcal U_t, R_t is coherent on any admitted loss domain closed under addition and scalar multiplication and containing deterministic cash losses. The numerical upper bound need not itself be coherent if its allowances vary freely across portfolios.

Proof. For every threshold v, the hinge x\mapsto(x-v)_+ is 1-Lipschitz. Any coupling bounds the difference of its expectations by \mathbb{E}|X-Y|. Taking the coupling infimum bounds the two ES minimands uniformly by W_1/q. Taking their threshold infima proves the ES bound. Also \sup_{\nu\in\mathcal U_t}\mathbb{E}_\nu|\ell_\Pi| \le\mathbb{E}_{\widehat P_t}|\ell_\Pi|+\eta_t(\Pi)<\infty. Taking the supremum over \mathcal U_t and adding numerical error proves the displayed certificate. Each fixed-law ES is coherent. Its supremum over a common set preserves monotonicity, translation invariance, and positive homogeneity. For subadditivity, bound each law’s ES of a sum by its two component values, then by their separate suprema. ◻

A cumulative distribution function (CDF) gives the probability that a loss is at most a specified amount. When losses lie in a bounded interval, a uniform CDF error supplies a simple transport-distance certificate.

Corollary 4.6 (Bounded-loss CDF certificate).

If both loss laws are supported on [a,b] and their CDFs differ by at most \beta, then W_1(P,\widehat P)=\int_a^b|F_P(x)-F_{\widehat P}(x)|\,dx \le(b-a)\beta. Their ES difference is at most \min\{b-a,(b-a)\beta/q\}. This is a bounded-loss corollary of the integrable-loss result.

Remark 4.7 (Calibration and automatic computation).

For J finite scenarios, let \mathcal U_t be a nonempty closed probability polytope. For scenario losses \ell_j, the robust ES is the linear-program value R_t(\Pi)=\max_{p,z}\left\{\sum_{j=1}^Jz_j\ell_j: p\in\mathcal U_t,\ z_j\ge0,\ \sum_jz_j=1,\ qz_j\le p_j\right\}. For fixed p, qz allocates the worst q probability mass, including fractional atoms. Maximising over p proves the identity. A solver supplies a primal feasible value and a dual feasible upper value, with residual and rounding allowances recorded in currency units. The certified upper value can supply the margin charge, subject to those allowances. Merely sampling laws gives a lower bound on this maximum.

One finite-scenario calibration uses n independent horizon outcomes from one fixed physical scenario law. With empirical frequencies \widehat p_j, define \mathcal U_t=\{p\ge0:\ \sum_jp_j=1,\ |p_j-\widehat p_j|\le r_n\}, \quad r_n=\sqrt{\log(2J/\alpha)/(2n)}. The Bernoulli exponential bound for each scenario indicator is \Pr(|\widehat p_j-p_j|>r)\le2e^{-2nr^2}. A union bound gives coverage at least 1-\alpha for the whole probability vector. Consequently this common set covers every portfolio on those scenarios simultaneously. The certificate must justify independent observations, the fixed horizon law, and complete scenario support. Overlapping horizons or an unmodelled regime change require another coverage argument.

For an unbounded loss, finite-radius calibration must also control the loss tails. Write T_\nu(M):=\mathbb{E}_\nu(|\ell_\Pi|-M)_+ for M>0. If every candidate law has T_\nu(M)\le T(M) and the clipped-loss CDF differs from the forecast’s by at most \beta, then W_1(\nu_\Pi,\widehat P_{t,\Pi}) \le T(M)+T_{\widehat P_t}(M)+2M\beta. Clipping each loss to [-M,M] gives the two tail costs. The intervening CDF bound gives 2M\beta. This supplies a finite loss-law certificate when its tail envelope and simultaneous CDF coverage have evidentiary support. Integrability ensures each true tail cost tends to zero, but finite observations alone do not provide its distribution-free upper bound.

For example, take losses 0 and 100, q=0.01, and forecast tail probability 0.0005. Let the physical tail probability lie in [0.0004,0.0006]. Then \eta=0.01, forecast ES is 5, and robust ES is 6. This is a nonzero finite charge under an explicit calibration interval. Current pricing agreement does not establish that interval. Discretisation, optimisation, and rounding require their own numerical allowances. Proposition 4.12 applies when its density and loss assumptions hold. An upper margin requirement remains a receivable until collateral funds it.

4.2 Constructing a price law with an attained optimizer

The margin calculations above distinguish prices from forecasts. A price law itself must still exist under the constraints used to compute it. The next construction chooses a law that satisfies specified average-payoff constraints while balancing cost against distance from a reference law. Relative entropy, written D_{\mathrm{KL}}, measures that distance and is infinite when the required density or integrability fails. A finite-entropy feasible law is therefore a substantive premise. This is an additional pricing mechanism with a separately specified reference law, cost, and moment constraints. The reserve invariant supplies liquidation proceeds. It does not determine these additional pricing inputs.

Theorem 4.8 (Attained entropy-potential clearing).

Let \Omega be compact metric, \mu_0 a fixed probability law, and \tau>0 a currency-valued parameter. Let the currency-valued cost c and the finite families g_i,h_k be continuous. Define \mathcal C=\left\{\mu\in\mathcal P(\Omega): \int g_i\,d\mu=b_i,\quad \int h_k\,d\mu\leq d_k\right\}. Assume a feasible law has finite relative entropy against \mu_0. Then Q(c)=\mathop{\mathrm{arg\,min}}_{\mu\in\mathcal C} \left\{\tau D_{\mathrm{KL}}(\mu\Vert\mu_0)+\int c\,d\mu\right\} exists, is unique, and has finite objective. The same conclusion holds on a Polish space with bounded continuous constraints and a lower-bounded, lower-semicontinuous coercive cost. For that extension, require one finite-objective feasible law and compact cost sublevel sets.

Proof. On compact \Omega, probability laws are weakly compact and the moment constraints form a closed convex set. Relative entropy is weakly lower semicontinuous by its variational representation. The linear cost is continuous, so a minimizing sequence has a feasible limit attaining the finite infimum. Strict convexity of relative entropy on its finite domain gives uniqueness. On the Polish space, subtract the lower bound of c. An objective sublevel bounds \int c\,d\mu, and hence bounds the mass outside each compact cost sublevel. The sequence is tight. Prokhorov compactness and lower semicontinuity give attainment, followed by the same uniqueness argument. Unbounded constraint functions require separate uniform-integrability control before their moments pass to the limit. ◻

An indicator payoff can jump at a contractual boundary, so continuity of every constraint would exclude useful contracts. The next result admits bounded measurable payoffs while retaining the reference law’s treatment of boundary probabilities.

Corollary 4.9 (Measurable clearing contracts).

The same entropy mechanism admits bounded measurable cost and constraint functions on a fixed probability reference space. Require densities f=d\mu/d\mu_0\geq0 with \int f\,d\mu_0=1 and one finite-entropy feasible density. Then it has a unique minimizing density. Digital and barrier indicators can appear in the constraints. The reference law specifies any boundary atoms that clearing can allocate positive mass to.

Proof. A bounded objective bounds entropy because the cost is bounded below. Entropy sublevels are uniformly integrable since x\log x grows faster than x. The Dunford–Pettis criterion gives weak compactness in L^1(\mu_0). Positivity, normalization, and bounded measurable moment constraints are weakly closed. Entropy is weakly lower semicontinuous, and the cost is weakly continuous. A minimizing sequence therefore attains its finite infimum. Strict convexity gives uniqueness. ◻

For computation, divide the outcome space into cells and choose each cell’s total probability. Within a cell, retain the reference law’s conditional distribution. This construction lifts the finite probability vector to a full outcome law. A feasible candidate gives an upper objective value, and the dual multipliers give a lower value. Their gap bounds the optimizer’s error.

Proposition 4.10 (Finite entropy lift and numerical certificate).

Partition \Omega into finitely many measurable cells C_j with \pi_j=\mu_0(C_j)>0. Require every cell coefficient A_{ij}, H_{kj}, and c_j below to be finite and real. For p in the probability simplex define \mu_p=\sum_j p_j\mu_0(\cdot\mid C_j). Use exact cell averages A_{ij}=\mathbb{E}_{\mu_0}[g_i\mid C_j], H_{kj}=\mathbb{E}_{\mu_0}[h_k\mid C_j], and c_j=\mathbb{E}_{\mu_0}[c\mid C_j]. On a nonempty polytope Ap=b, Hp\leq d, the restricted objective is F_c(p)=\tau\sum_jp_j\log(p_j/\pi_j)+c^\top p, with 0\log0=0, and has a unique optimizer p^*. For a feasible p and any multipliers \lambda, \eta\geq0, define U=F_c(p),\qquad D=-\lambda^\top b-\eta^\top d -\tau\log\sum_j\pi_j \exp\!\left[-\frac{c_j+(A^\top\lambda)_j+(H^\top\eta)_j}{\tau}\right]. Then G:=U-D\geq0 and \|p-p^*\|_1\leq\sqrt{2G/\tau}. For cell payoffs of range V, the price error is at most V\sqrt{G/(2\tau)}. For cell losses of range B, the ES error is at most B\sqrt{G/(2\tau)}/q.

Proof. The lift has constant density p_j/\pi_j on each cell, giving the entropy identity and exact moment constraints. Compactness and strict convexity give the finite optimizer. Minimizing the Lagrangian over the simplex gives the displayed dual lower bound. Entropy is 1-strongly convex in \ell^1 by Pinsker’s inequality, so F_c(p)-F_c(p^*)\geq\tau\|p-p^*\|_1^2/2. Use F_c(p^*)\geq D and the range-times-total-variation bounds for price and ES. ◻

Remark 4.11 (Clearing solver outcomes).

The solver distinguishes an empty feasible set, a missing finite-feasibility certificate, and a feasible solution with an explicit primal-dual gap. Integral and rounding allowances enter both objective bounds and moment residuals. A corrected feasible point is required before its lift represents cleared moments. An atomic grid is different from the lift and can have infinite entropy against a continuous reference law. A finite optimizer solves its stated restriction. Convergence to the unrestricted law additionally requires a feasible approximation scheme and controlled objective error. On [0,1] with uniform reference, the moment constraint \mathbb{E}[X]=0 permits only \delta_0, which has infinite entropy. The finite-feasibility condition excludes that case from the theorem. A constraint \mathbb{E}[X]=2 is infeasible.

4.3 Quadrature error bound

For numerical evaluation, \mathrm{ES}_q^{\mu_t} is evaluated on a finite quadrature grid \{\omega_j\}_{j=1}^J with weights \{w_j\} satisfying \sum_j w_j = 1. The discretisation error is bounded by standard quadrature theory.

Proposition 4.12 (Quadrature error bound).

Let \Omega=[a,b]^d. Let \mu_t have a density (also written \mu_t) with \mathrm{Lip}(\mu_t) \leq L_\mu, and let \ell_\Pi be bounded and Lipschitz with constant L_\ell. Partition \Omega into J=m^d equal cubes Q_j of side h=(b-a)/m, and choose one node \omega_j in each cube. Set \widetilde w_j:=\mu_t(\omega_j)|Q_j|, Z_J:=\sum_j\widetilde w_j, and w_j:=\widetilde w_j/Z_J. Assume m is large enough that L_\mu\sqrt d\,h\,\operatorname{vol}(\Omega)\leq 1/2, which implies Z_J\geq1/2. Write \hat{\mathrm{ES}}_q^J[\Pi] := \mathrm{ES}_q^{\hat\mu_J}[\Pi] for the value of (21) on \hat\mu_J := \sum_j w_j\,\delta_{\omega_j}. The infimum runs over the grid loss values, and an atom at the grid quantile enters with the fractional weight of (21). Then \bigl|\mathrm{ES}_q^{\mu_t}[\Pi] - \hat{\mathrm{ES}}_q^J[\Pi]\bigr| \;\leq\; C_{d,\Omega}\cdot \frac{L_\ell+\|\ell_\Pi\|_\infty L_\mu}{q}\cdot J^{-1/d}, \tag{22} for a constant C_{d,\Omega}>0 depending only on d and \Omega.

Proof sketch. Let p_j:=\mu_t(Q_j) and let \hat\mu_J^{\mathrm{cell}}:=\sum_jp_j\delta_{\omega_j} carry each cell’s exact mass to its node. Two continuity properties of Expected Shortfall carry the proof. On the real line, ES is the average of the upper q-quantiles. Thus \mathop{\mathrm{ES}}_q(F)=q^{-1}\int_{1-q}^{1}F^{-1}(u)\,du, \qquad |\mathop{\mathrm{ES}}_q(F)-\mathop{\mathrm{ES}}_q(G)|\leq q^{-1}W_1(F,G). The representation (21) also gives |\mathrm{ES}_q^{\mu}[\Pi]-\mathrm{ES}_q^{\nu}[\Pi]| \leq2\|\ell_\Pi\|_\infty q^{-1}d_{\mathrm{TV}}(\mu,\nu). Coupling every point in Q_j to \omega_j gives W_1(\mu_t,\hat\mu_J^{\mathrm{cell}})\leq\sqrt d\,h. The L_\ell-Lipschitz loss map therefore gives |\mathrm{ES}_q^{\mu_t}[\Pi]-\mathrm{ES}_q^{\hat\mu_J^{\mathrm{cell}}}[\Pi]|\leq L_\ell\sqrt d\,h/q. Before normalisation, Lipschitz continuity gives |\widetilde w_j-p_j|\leq L_\mu\sqrt d\,h|Q_j|. Thus E_J:=\sum_j|\widetilde w_j-p_j|\leq L_\mu\sqrt d\,h\operatorname{vol}(\Omega) and |Z_J-1|\leq E_J. Since Z_J\geq1/2, \sum_j|w_j-p_j|\leq Z_J^{-1}\bigl(E_J+|Z_J-1|\bigr)\leq4E_J. The total-variation bound controls the second difference by a constant times \|\ell_\Pi\|_\infty L_\mu h/q. Adding the two bounds and substituting h=(b-a)J^{-1/d} gives (22). The quantile level set needs no regularity. If the loss is flat on positive mass at the quantile, the fractional-atom rule in (21) remains necessary; summing every grid weight on \{\ell_\Pi\geq\hat v_q\} can incur an O(1) error. ◻

A grid that ignores a payoff jump can miss the loss even when it approximates smooth prices accurately. The next bound charges separately for representing losses within cells and for assigning the wrong probability mass to cells.

Proposition 4.13 (Jump-aware and atom-aware quadrature).

Partition the state space into measurable cells C_j with exact masses p_j. Choose representative losses l_j\in[a,b] and normalized approximate masses w_j. Suppose D_J\geq\sum_j\int_{C_j}|L-l_j|\,d\mu, \qquad T_J=\tfrac12\sum_j|p_j-w_j|. For integrable L, \left|\mathop{\mathrm{ES}}_q^\mu(L)-\mathop{\mathrm{ES}}_q^{\sum_jw_j\delta_{l_j}}\right| \leq\frac{D_J+(b-a)T_J}{q}. For L=g+\sum_k A_k\mathbf1_{D_k} with Lipschitz g, the within-cell allowance includes \mathrm{Lip}(g)\sum_jp_j\operatorname{diam}(C_j) and |A_k| times the mass of cells whose membership in D_k differs from their representative. Boundary atoms follow the payoff’s specified strict or weak inequality.

Proof. Couple every state in C_j to l_j to bound loss-law W_1 by D_J. Changing cell masses moves at most T_J mass across a loss range b-a. Apply the hinge-based W_1/q ES bound to both changes. The smooth and jump estimates bound the within-cell absolute difference separately. ◻

Remark 4.14 (Nonlinear and unbounded loss examples).

For uniform X on (0,1), 1/X has infinite expectation and does not satisfy the ES integrability premise. The loss 1/\sqrt X is integrable and has \mathop{\mathrm{ES}}_q=2/\sqrt q. Clipping it at M\geq1/\sqrt q leaves expected remainder 1/M and ES error exactly 1/(Mq). Thus an unbounded loss admits a finite grid with an explicit tail allowance. For 100\mathbf1_{X>0.995} at q=0.01, exact ES is 50. A midpoint grid with a node at the strict boundary can give zero. Partitioning at 0.995 and retaining the exact masses recovers 50. For masses 0.993 below, 0.002 on, and 0.005 above the boundary, ES is 50 under > and 70 under \geq. The fractional-quantile rule in (21) applies after either allocation.

Remark 4.15 (Tail resolution).

The 1/q factor in (22) reflects tail-event localisation at small q: meeting a fixed error tolerance \varepsilon requires on the order of J = O\bigl((\varepsilon q)^{-d}\bigr) nodes on a uniform grid. Adaptive quadrature or importance-sampled grids concentrated near the tail boundary relax this cost; the stress catalogue \Omega_0 of Definition 6.24 supplies a non-adaptive tail-biased grid.

4.4 Compatibility with the parametric ES

Remark 4.16 (Pricing, forecasting, and numerical validation).

The clearing law Q_t prices payoffs and supplies pricing diagnostics. The physical forecast \widehat P_t and common uncertainty set \mathcal U_t supply M^{\mathrm{cont}}. The streaming return fit supplies M^{\mathrm{param}}. The independent scenario catalogue supplies M^{\mathrm{stress}}. Physical backtests compare forecasts with subsequent realised horizon outcomes. Numerical validation bounds integration or optimisation error under the law actually used. Agreement with the venue’s pricing law does not establish physical calibration.

4.5 Robustness to state-price-density manipulation

The pricing law is an output of a clearing estimator that observes trade flow. A certified contamination model can bound a pricing diagnostic. A physical-margin guarantee additionally needs a stability bound for the induced physical uncertainty sets.

Proposition 4.17 (Pricing-diagnostic sensitivity under a contamination contract).

Write d_{\mathrm{TV}}(\mu, \nu) := \sup_A |\mu(A) - \nu(A)| \in [0, 1]. Let \mu_t^* be a reference pricing law. Assume the estimator has a certified output contract \mu_t=(1-\alpha)\mu_t^*+\alpha\nu, where 0\le\alpha<1 and \nu is a probability law. Here \alpha is an output-contamination weight. A trading-volume fraction bounds \alpha only through an additional verified estimator response bound. For bounded \ell_\Pi, \bigl|\mathrm{ES}_q^{\mu_t}[\Pi] - \mathrm{ES}_q^{\mu_t^*}[\Pi]\bigr| \;\leq\; \frac{2\,\|\ell_\Pi\|_\infty}{q}\; d_{\mathrm{TV}}(\mu_t, \mu_t^*) \;\leq\; \frac{2\alpha\, \|\ell_\Pi\|_\infty}{q}, \tag{23} and the constant is sharp. For q = 0.01 and \|\ell_\Pi\|_\infty \leq L the pricing diagnostic moves by at most 200\,\alpha L: linear in \alpha.

Proof. By the Rockafellar-Uryasev representation, \mathrm{ES}_q^{\mu}[\Pi]=\min_v\left\{v+q^{-1}\int(\ell_\Pi-v)_+\,d\mu\right\}, and a minimiser lies in [-\|\ell_\Pi\|_\infty,\|\ell_\Pi\|_\infty]. For 0\leq h\leq H, \left|\int h\,d(\mu-\nu)\right| \leq\int_0^H|\mu(h>u)-\nu(h>u)|\,du \leq H\,d_{\mathrm{TV}}(\mu,\nu). Use h=(\ell_\Pi-v)_+ and H\leq2\|\ell_\Pi\|_\infty. The two minimands differ by at most 2\|\ell_\Pi\|_\infty d_{\mathrm{TV}}/q at every relevant v, hence so do the minima. The mixture has d_{\mathrm{TV}}(\mu_t,\mu_t^*)=\alpha d_{\mathrm{TV}}(\nu,\mu_t^*)\leq\alpha. Sharpness follows from \mu_t^*=\delta_{-L} and \nu=\delta_L with \alpha\leq q, which give a gap of 2\alpha L/q. ◻

The contamination contract alone does not explain how trades affect an estimated law. For the finite entropy mechanism, the next result connects a bounded change in observed input features to a change in its computed prices. Its constraint set and reference weights stay fixed throughout the comparison.

Proposition 4.18 (Certified flow influence for entropy clearing).

Use the finite mechanism of Proposition 4.10 with fixed feasible polytope, prior weights \pi, and \tau. For its exact solutions, \|p(c)-p(c')\|_1\leq\frac{\|c-c'\|_\infty}{\tau}, \qquad d_{\mathrm{TV}}(p(c),p(c'))\leq\frac{\|c-c'\|_\infty}{2\tau}. Suppose the recorded estimator uses c_j(v)=c_j^0+\int\phi_j(z)\,v(dz) with |\phi_j(z)|\leq G. If the admitted normalized input law satisfies v=(1-\alpha)v_*+\alpha v_A, then d_{\mathrm{TV}}(p(c(v)),p(c(v_*)))\leq\min\{1,G\alpha/\tau\}. Here G and \tau have currency units. The input law and feature aggregation define when a measured volume share equals \alpha. A change to constraints, prior weights, or normalization requires a separate certificate.

Proof. Entropy strong convexity and the two optimality inequalities give \tau\|p-p'\|_1^2\leq(c-c')^\top(p'-p). Hölder’s inequality gives the first bound, including the case p=p'. Total variation is half the \ell^1 distance. The recorded mixture changes each feature average by at most 2G\alpha. Substitute this coefficient bound. For approximate solvers, add their two certified \ell^1 errors from Proposition 4.10 before dividing by two. ◻

To propagate that sensitivity into margin, specify how the computed probabilities weight candidate physical laws. The next result controls the resulting sets of monetary loss distributions. Their Hausdorff distance bounds how far any law in either set lies from a matching law in the other.

Proposition 4.19 (Physical mixture-set response certificate).

Let \mathcal V_j be fixed nonempty sets of physical state laws, common to all portfolios, and define \mathcal U(p)=\{\sum_jp_j\nu_j:\nu_j\in\mathcal V_j\}. For a fixed portfolio loss \ell_\Pi, assume \sup_{j,\nu\in\mathcal V_j}\int|\ell_\Pi|\,d\nu\leq M<\infty. Then the Hausdorff W_1 distance between their induced scalar-loss-law sets is at most 2M d_{\mathrm{TV}}(p,p'). A smaller certified pairwise transport diameter D replaces 2M by D. Thus the robust physical ES changes by at most D G\alpha/(\tau q) under Proposition 4.18. The positive buffered margin changes by at most (1+\zeta)D G\alpha/(\tau q). Physical coverage of the true loss law in \mathcal U(p) remains a separately calibrated premise.

Proof. For each selected tuple (\nu_j), retain the common mass \min(p_j,p_j') in every component. The remaining total mass is d_{\mathrm{TV}}(p,p'). Couple its source and destination components with cost at most 2M, or the certified D. This gives a matching law in the other set. Reverse the argument for the Hausdorff bound. The hinge ES bound and the 1-Lipschitz positive-part map give the margin bounds. Uniform bounds over selectable portfolios are required when their selection is adaptive. ◻

Proposition 4.20 (Physical-margin stability under uncertainty-set perturbation).

Fix the same portfolio loss, horizon, tail mass q, and buffer \zeta for two physical uncertainty sets. Let \mathcal A and \mathcal B be their nonempty sets of scalar loss laws, each with finite first moments. Assume both robust ES suprema are finite. Define their Hausdorff loss-law distance by d_H^{W_1}(\mathcal A,\mathcal B):= \max\left\{\sup_{P\in\mathcal A}\inf_{Q\in\mathcal B}W_1(P,Q), \sup_{Q\in\mathcal B}\inf_{P\in\mathcal A}W_1(P,Q)\right\}. If this distance is at most \delta, then |R(\mathcal A)-R(\mathcal B)|\le\delta/q, \qquad |M^{\mathrm{cont}}(\mathcal A)-M^{\mathrm{cont}}(\mathcal B)| \le(1+\zeta)\delta/q. Here R(\mathcal A):=\sup_{P\in\mathcal A}\mathop{\mathrm{ES}}_q(P) and M^{\mathrm{cont}}(\mathcal A):=(1+\zeta)[R(\mathcal A)]_+, with corresponding definitions for \mathcal B. The distance certificate must be uniform over selectable portfolios when selection is adaptive.

Proof. For each P\in\mathcal A and \epsilon>0, choose Q\in\mathcal B with W_1(P,Q)\le\delta+\epsilon. Proposition 4.5 gives \mathop{\mathrm{ES}}_q(P)\le R(\mathcal B)+(\delta+\epsilon)/q. Take the supremum over P, then let \epsilon\downarrow0. Reverse the sets for the absolute bound. The positive-part function is 1-Lipschitz, which proves the margin bound. ◻

Here and below, B_t denotes the largest of the floor, stress, and physical-risk requirements at time t. Definition 5.16 gives its formula after the estimator and health checks have been specified.

Remark 4.21 (Flow limits, response certificates, and model health).

A flow cap supplies a pricing-diagnostic bound only when the estimator maps that flow budget to a certified contamination weight. If pricing features alter the physical forecast or uncertainty set, Proposition 4.20 supplies the required physical-margin bound. Its certificate must bound the induced loss-law-set distance, including recalibration and portfolio selection effects. A bound on the pricing law alone does not supply that distance. The system can apply these bounds automatically when the stated estimator and uncertainty-set contracts hold. Backtests use their specified acceptance rules and physical outcome data. Their detection probabilities require calibration and do not guarantee detection of every margin gap. A detected health failure sets degraded operation. Equation (27) retains the preceding requirement and applies current increases in B_t. Numerical checks validate the bounds used by each layer.

5 Streaming Correlation Estimation with Change-Point Reset

The parametric ES of (2) requires a correlation matrix \mathbf{P}. This section specifies its estimator: a streaming sample covariance on the observed fill stream, a generalised-likelihood-ratio change-point test that resets the estimator after a detected correlation-regime shift, and sequential physical-tail checks that enter degraded operation after a detected failure. Among all distributions on \mathbb{R}^p matching the estimated first and second moments, the maximum-entropy distribution is the multivariate Gaussian, so the fit imputes no dependence structure beyond the estimated first and second moments; downstream layers treat the output as a Gaussian correlation model, subject to the defense-in-depth stack of §5.5.

Positioning relative to Definition 5.16: the streaming fit is the correlation source inside the M^{\mathrm{param}} layer, replacing the ad hoc sample-plus-prior blend of Remark 3.11. It does not itself provide solvency protection; the floor, stress, and certified physical-risk layers supply additional requirements. Its role is to make M^{\mathrm{param}} follow realised dependence in normal regimes, so that M^{\mathrm{req}}(\Pi) = \max(M^{\mathrm{floor}}, M^{\mathrm{param}}, M^{\mathrm{stress}}, M^{\mathrm{cont}}) can bind at M^{\mathrm{param}} in normal operation, and retains the preceding requirement with increases in B_t during degraded operation.

5.1 Estimator and sample complexity

Definition 5.1 (Streaming covariance estimator).

Let \{r^{(t)}\} denote per-fill return observations on p spoke assets. The estimator maintains the running mean and covariance by Welford’s update [64], which requires O(p^2) memory, needs no stored fill history, and is numerically stable under the catastrophic cancellation that near-cancelling fills induce in a naive variance recursion. The correlation matrix \hat{\mathbf{P}}_T is the normalisation of the running covariance \hat{\boldsymbol\Sigma}_T after T fills.

The estimation bound assumes independent, identically distributed observations, abbreviated i.i.d. A sub-Gaussian assumption bounds exponential moments of centered observations and controls unusually large errors. The Frobenius norm \|\cdot\|_F is the square root of the sum of squared matrix entries. The probability statement below bounds that aggregate correlation error under these assumptions.

Proposition 5.2 (Sample complexity).

Let \{r^{(t)}\}_{t=1}^T be i.i.d., centred vectors with unit coordinate variances, correlation matrix \mathbf P^*, and uniform sub-Gaussian norm \max_i\|r_i^{(t)}\|_{\psi_2}\leq K. For \varepsilon\in(0,1) and \delta\in(0,1) there is a constant c_1(K) depending only on K such that T \;\geq\; c_1\cdot \frac{p\log(p/\delta)}{\varepsilon^2} \quad\Longrightarrow\quad \mathbb{P}\bigl(\|\hat{\mathbf{P}}_T - \mathbf{P}^*\|_F \leq \varepsilon\sqrt{p}\bigr) \;\geq\; 1 - \delta. \tag{24}

Proof. Each centred product r_i^{(t)}r_j^{(t)}-P^*_{ij} is sub-exponential with norm bounded by a constant depending only on K. Bernstein concentration and a union bound over p^2 covariance entries therefore give entrywise error at most c(K)\sqrt{\log(p^2/\delta)/T}. The sample variances obey the same bound. On the event that every variance error is below 1/2, normalising the sample covariance to a correlation matrix changes the constant but not the rate. Taking the entrywise error at most \varepsilon/\sqrt p and summing its square over p^2 entries gives the Frobenius bound. The stated sample size makes both events hold with probability at least 1-\delta [41]. ◻

5.2 Misspecification-robustness bound

The Gaussian fit matches first and second moments only. Fill streams may carry higher-order dependence, in which case the fit misspecifies the joint distribution. We bound the margin gap this introduces.

Proposition 5.3 (Margin gap under misspecification).

Let p^* denote the true joint distribution and p_G the Gaussian with p^*’s first and second moments (the KL projection of p^* onto the Gaussian family). Assume the portfolio loss \ell_\Pi is bounded and \varepsilon_{\mathrm{KL}} := \mathrm{KL}(p^*\| p_G)<\infty. Then \bigl|\mathrm{ES}_q^{p^*}[\Pi] - \mathrm{ES}_q^{p_G}[\Pi]\bigr| \;\leq\; \frac{\|\ell_\Pi\|_\infty}{q}\cdot \sqrt{2\varepsilon_{\mathrm{KL}}}, \tag{25} by Pinsker’s inequality [66]. When \varepsilon_{\mathrm{KL}} grows — regime transitions that introduce higher-order dependence are one driver — the parametric-layer margin becomes a biased estimate of the realised tail loss, and the degraded rule of Definition 5.16 retains the preceding requirement and applies stress increases.

Proof. By Proposition 4.17, |\mathrm{ES}_q^{p^*} - \mathrm{ES}_q^{p_G}| \leq (2\|\ell_\Pi\|_\infty/q)\, d_{\mathrm{TV}}(p^*, p_G), and Pinsker’s inequality gives d_{\mathrm{TV}} \leq \sqrt{\varepsilon_{\mathrm{KL}}/2}. ◻

Remark 5.4 (Response to detected estimator breakdown).

The health predicate checks fit conditioning and realized tail losses. A failed check enters degraded operation under Definition 5.16. The circuit breaker halts new risk and retains the preceding requirement. Current increases in B_t remain effective. These tests detect specified failures after observation and do not establish detection of every model error.

5.3 Regime-shift detection and estimator reset

Proposition 5.2 assumes i.i.d. samples. Fill streams may exhibit regime shifts — discrete changes in the underlying correlation structure — that violate the i.i.d. assumption and degrade the estimator. The detector is a standard two-window generalised-likelihood-ratio change-point test.

The detector compares how well one Gaussian model fits both windows against two models fitted separately. A large improvement from the separate fits is evidence against an unchanged regime. A finite-sample guarantee for repeated use requires the additional calibration and total error budget stated after the definition.

Definition 5.5 (Regime-shift detector).

A regime-shift detector compares two rolling windows of size W>p: \mathcal W_1(t):=\{r^{(t-W+1)},\ldots,r^{(t)}\}, \qquad \mathcal W_2(t):=\{r^{(t-2W+1)},\ldots,r^{(t-W)}\}. The null hypothesis states that the two windows are independent samples from one non-degenerate Gaussian. With \boldsymbol\theta = (\boldsymbol\mu, \boldsymbol\Sigma) and \ell the Gaussian log-likelihood, the generalised-likelihood-ratio statistic \Lambda_t \;:=\; 2\bigl[\ell(\hat{\boldsymbol\theta}^{(1)};\mathcal W_1(t)) + \ell(\hat{\boldsymbol\theta}^{(2)};\mathcal W_2(t)) - \ell(\hat{\boldsymbol\theta}^{\mathrm{pool}};\mathcal W_1(t)\cup\mathcal W_2(t))\bigr] \tag{26} is asymptotically \chi^2_{d_\theta} under the null, with d_\theta = p + p(p+1)/2 the parameter dimension. A regime-shift detection at level \alpha rejects the null when \Lambda_t > \chi^2_{d_\theta, 1-\alpha}.

Proposition 5.6 (Repeated regime tests with a lifetime error budget).

Fix deterministic levels \alpha_j\geq0 with \sum_j\alpha_j\leq\alpha<1. At test index j, use a valid null p-value p_j. If each null test obeys \Pr(p_j\leq\alpha_j)\leq\alpha_j, the probability of any false rejection is at most \alpha. This includes overlapping windows and estimator epochs covered by the same budget. For independent, identically distributed pooled observations under the Gaussian null, an exact permutation distribution of the two-window statistic supplies a finite-sample p-value. The asymptotic chi-square cutoff alone does not provide that finite-sample certificate.

Proof. The union bound gives \Pr(\exists j:p_j\leq\alpha_j)\leq\sum_j\alpha_j. Under the pooled null, assigning the observations to the two equal windows is exchangeable. The fraction of admissible assignments with statistic at least the observed statistic is a conservative null p-value, including ties. If levels depend on earlier observations, use conditional super-uniformity for the corresponding conditional test or fix the levels in advance. ◻

Counting false alarms over the life of the monitor requires a statistic that remains valid under repeated inspection. The product below starts at one and has conditional expectation no greater than its preceding value under the stated calibration contract. Such a process is a nonnegative supermartingale. Its threshold crossing supplies the lifetime alarm bound.

Proposition 5.7 (Sequential physical-tail calibration checks).

At outcome time t, let Y_t\geq0 have a predictable budget b_t>0 with \mathbb{E}[Y_t\mid\mathcal F_{t-1}]\leq b_t. For predictable \lambda_t\in[0,1], define E_n=\prod_{t=1}^n\left[1+\lambda_t\left(\frac{Y_t}{b_t}-1\right)\right], \qquad E_0=1. Then E_n is a nonnegative supermartingale. For \alpha\in(0,1), \Pr(\sup_n E_n\geq1/\alpha)\leq\alpha. Two useful score contracts are \begin{array}{lll} Y_t=\mathbf1_{\{L_t>v_t\}},&b_t=q_t,&\text{quantile exceedance},\\ Y_t=(L_t-v_t)_+,&b_t=q_t(m_t-v_t)>0,&\text{ES threshold score}. \end{array} The forecast v_t, ES upper forecast m_t, and tail mass q_t\in(0,1) are fixed before observing L_t. The second contract bounds the threshold objective v_t+\mathbb{E}[(L_t-v_t)_+\mid\mathcal F_{t-1}]/q_t by m_t. It tests tail magnitude in addition to exceedance frequency.

Proof. Each multiplier is nonnegative and has conditional expectation at most one. Iterated conditioning proves the supermartingale property. Stop at the first crossing of 1/\alpha, truncated at a finite horizon. Its expectation is at most one, so the crossing probability is at most \alpha. Monotone convergence of the crossing events gives the lifetime bound. The two stated scores are nonnegative and satisfy the theorem under their respective conditional calibration contracts. Integrability suffices for the ES score. ◻

Corollary 5.8 (Finite detection probability in a Bernoulli shift).

Suppose Y_t=I_t or Y_t=cI_t for independent I_t\sim\operatorname{Bernoulli}(p_1), while its null budget uses p_0<p_1<1. Taking \lambda=(p_1-p_0)/(1-p_0) gives E_n=(p_1/p_0)^{K_n}\{(1-p_1)/(1-p_0)\}^{n-K_n}, \qquad K_n=\sum_{t=1}^n I_t. Let k_n be the smallest integer in \{0,\ldots,n\} for which the expression at K_n=k_n is at least 1/\alpha. Set k_n=n+1 if no such integer exists. The probability of detection by n is at least \Pr\{\operatorname{Binomial}(n,p_1)\geq k_n\}.

Proof. Substitute the stated bet into the two possible multipliers. Their product is the displayed likelihood ratio, increasing in K_n. Crossing at time n implies detection by time n. ◻

Remark 5.9 (Calibration records and reset budgets).

Each score record binds the forecast, observation horizon, data cutoff, portfolio, model version, and conditional error contract. Multiple score processes can share a fixed convex mixture or a preassigned total false-alarm budget. A reset starts a new epoch only with an explicit remaining budget. A detected failure enters the existing degraded recurrence and preserves funded-resource accounting. A failure to reject does not certify every model component. Power outside a specified alternative is measured on held-out data or remains an unresolved empirical quantity. The deterministic synthetic package reports those distinctions.

Definition 5.10 (Estimator reset after a detected regime shift).

Under the regime-shift detector of Definition 5.5 with detection probability at least 1 - \beta for a true shift of magnitude \|\Delta\boldsymbol\theta\|_2 \geq \kappa_{\mathrm{reg}}:

(i)

On detection at time t, the estimator is reset: pre-t fills are excluded from the new fit.

(ii)

The health predicate \mathcal{H} of Definition 5.16 holds the parametric layer M^{\mathrm{param}} off until the reset window meets the sample-complexity requirement of Proposition 5.2.

(iii)
During the hold-off, the degraded rule retains the preceding requirement and applies increases in B_t.

Remark 5.11 (Regime-shift interacts with tier transition).

A compliance-tier transition (Definition 7.3) changes the eligible-counterparty set and can change realised correlations. The transition signal sets \mathcal H to false and resets the estimator directly; the statistical detector is only a secondary check. The atomic re-margin of Definition 7.3 completes before the parametric layer re-engages.

Remark 5.12 (Sensitivity to detector mis-tuning).

At fixed windows, a larger test level \alpha lowers the rejection threshold and increases false resets. A smaller \alpha raises the threshold and can miss real shifts. A false reset retains the preceding requirement and applies increases in B_t. A missed shift can leave the parametric layer on stale data. The sequential scores in Proposition 5.7 provide separate calibrated detection opportunities. Both tests feed \mathcal{H}, and either can drop the parametric layer. Proposition 5.17 bounds the effect of an understated fit that passes both tests.

5.4 A persistent policy for inspection, reset, and admission

A repeated inspection changes what the operator knows. A reset changes which model it uses. Neither event restores an error allowance that an earlier decision has consumed. We make these distinctions explicit in one policy. The probability arguments use conditional Ville bounds [61] and the prospective union bound of Proposition 11.17. Their role is to permit adaptive operation under stated laws.

An epoch is an interval governed by one registered model and its testing allowance. A predictable quantity is fixed from available information before the next observation. The history keeps three probability allocations distinct: false alarms, failed certificates, and adverse economic outcomes of admitted actions.

Definition 5.13 (Persistent decision history).

Let \mathcal F_t contain all observations, model choices, inspections, and side information available at cutoff t. A persistent history records three distinct allocations: \sum_e a_e\le\alpha, \qquad \sum_c d_c\le\delta, \qquad \sum_j A_jq_j\le Q. Here a_e is an epoch’s false-alarm allowance, d_c is a simultaneous certificate’s failure allowance, and A_jq_j is an admitted action’s adverse-event allowance. All three inequalities hold on every history. An epoch records its model, fit, starting cutoff, conditional score law, allocation, and first eligible future observation. A forecast and its bet precede the observation they score. An admission records its selected action, current certificate, horizon, risk debit, and funded reservation. Repeated inspection leaves these allocations unchanged. Closing a model, restarting a process, or obtaining no fill leaves previous probability debits charged. Exact request replay returns the previous result. Changed requests require distinct identities and the remaining allowances.

Proposition 5.14 (Adaptive epochs with one false-alarm budget).

Epoch e starts at a stopping time \tau_e with allocation a_e\in(0,1) known at \tau_e. For t>\tau_e, its nonnegative score Y_{e,t} and predictable budget b_{e,t}>0 obey \mathbb{E}[Y_{e,t}\mid\mathcal F_{t-1}]\le b_{e,t} under its registered conditional null. Use the predictable multipliers of Proposition 5.7, starting from one at \tau_e. Inspection occurs at arbitrary times. An alarm records the first crossing of 1/a_e. Then the conditional probability of an alarm in epoch e is at most a_e. If \sum_e a_e\le\alpha on every history, the probability of any alarm under the joint null is at most \alpha. Independence between epochs is unnecessary.

Proof. Conditional on the starting history, each nonnegative multiplier has expectation at most one. Stop its product at the first crossing, truncated after N updates. Conditional optional sampling bounds its expectation by one. The threshold is known at registration, so the conditional crossing probability before that truncation is at most a_e. Increase N and use monotone convergence of crossing events. Finally, \Pr(\text{some alarm}) \le\sum_e\mathbb{E}[a_e] =\mathbb{E}\!\left[\sum_ea_e\right]\le\alpha. Unlaunched epochs have allocation zero in this sum. For mixed true and false nulls, the same argument bounds false alarms on starting histories whose conditional law belongs to the registered null family. This membership is a property of the conditional law at registration, not a retrospective classification from future outcomes. ◻

Window selection.

Two constructions preserve the stated bounds. A predictable test fixes its statistic and level before collecting the observations that justify its conditional test law. A simultaneous catalogue instead fixes all eligible windows and their coverage allocation before their data. After observation, any catalogue entry may be selected within that one simultaneous event. The catalogue does not cover a newly invented window or a different model merely because its numerical estimate looks favorable. Confidence sequences supply another simultaneous construction when their parameter and observation model satisfy the corresponding assumptions [62].

The finite-window estimator in Parlay Ising Couplings has one simultaneous coverage event [63]. Its failure allowance includes the statistical and drift contributions. The policy charges their sum once and preserves the catalogue identity across inspections and model restarts. A completed-window estimate describes the covered historical target. Selection does not convert its coverage into a conditional forecast at the selection time. The future-risk gate still requires the current, selected-action contract below.

Historical model coverage does not automatically bound the next selected trade. For an admission, the certificate must cover the future adverse event under the information used to choose that action. The next bound adds the probability that an authorized certificate fails to the adverse-event allowances charged by authorized actions.

Proposition 5.15 (Prospective admissions with simultaneous certificate coverage).

Action j is selected at stopping time \sigma_j. Its authorization A_j\in\{0,1\} and allowance q_j are \mathcal F_{\sigma_j}-measurable. Let B_j be its specified future adverse event and write p_j=\Pr(B_j\mid\mathcal F_{\sigma_j}), \qquad C_j=\{p_j>q_j\}. Suppose simultaneous coverage gives \Pr(\exists j:A_j=1,\ C_j)\le\delta, and \sum_jA_jq_j\le Q on every history. Then \Pr(\exists j:A_j=1,\ B_j)\le\delta+Q. The bound permits adaptive actions and overlapping horizons. It uses the conditional probability of each action actually selected.

Proof. For the fixed probability law, C_j is measurable at \sigma_j, even when the operator cannot observe its truth. Separate the event that some authorized certificate fails. For the other events, conditional expectation gives \mathbb{E}[A_j\mathbf1_{C_j^c}\mathbf1_{B_j}] =\mathbb{E}[A_j\mathbf1_{C_j^c}p_j] \le\mathbb{E}[A_jq_j]. The union bound and the pathwise allocation give the result. This proof does not condition the outcome law on a future coverage event. Such conditioning could change the probabilities being bounded. Catalogue coverage contributes to \delta only when its covered statement implies the required selected-action risk bound. A historical estimation guarantee alone does not supply that implication. ◻

A concrete gate.

Consider one-step binary adverse observations I_t. Before the next observation, register p_t\in(0,1) and a bet \eta_t\in[0,1/p_t]. Under the full-history conditional null \mathbb{E}[I_t\mid\mathcal F_{t-1}]\le p_t, update E_t=E_{t-1}\{1+\eta_t(I_t-p_t)\}. For an action at t, separately declare a current law bounding every future one-step adverse probability by p_0 throughout its horizon of W observations. Iterated conditioning and the union bound give q=\min\{1,Wp_0\} for that action’s declared adverse event. The gate requires this current contract, an unalarmed model, remaining allowance Q, and the existing funded-resource conditions. It atomically records the action and reserves its funded debit before dispatch. Observation, model change, or changed action terms require a fresh current certificate. The original admission remains fixed at its original cutoff.

The reference policy uses exact rational arithmetic and transactional persistent records. Its completed-window interface consumes the finite catalogue’s metadata and coverage allowance. Its prospective interface uses the declared conditional law above. The two interfaces carry different validity statements. An alarm closes the affected model to new risk. Funded baseline actions and closeout remain available under their own zero-additional-exposure contract. They lie outside the model-action adverse-event family charged against Q. Existing exposure can still realize losses during closeout. A probability bound for those losses requires its own event family and conditional certificate. A replacement model starts from the observed cutoff, charges a fresh a_e, and scores later observations. Resetting an estimator preserves collateral reservations and the degraded recurrence of Definition 5.16.

Detection and useful operation.

Take \alpha=1/20 and a_e=\alpha2^{-e} for e\ge1. In the first epoch, let p_t=1/100 and \eta_t=100/11. The multiplier is 10 on an adverse observation and 10/11 otherwise. Twenty ordinary observations leave the test statistic at (10/11)^{20}\simeq0.149. Three subsequent adverse observations raise it above the threshold 40. Under independent adverse probability 1/10, six adverse observations among the first 100 suffice for a crossing. Thus detection by 100 has probability at least \Pr\{\operatorname{Binomial}(100,1/10)\ge6\} =0.9424231135\ldots. With separate current action bounds q_j=1/10000, a lifetime allowance Q=1/100 supports 100 funded admissions. These allowances require the stated physical law and action mapping. The finite allowance does not support infinitely many actions at the same positive q_j.

The history rules prevent concrete statistical errors. Two independent uniform null p-values, selected by their minimum, reject at nominal level a with probability 2a-a^2. At a=0.05, that probability is 0.0975. Repeated fresh nominal budgets after reset amplify the same error. A forecast issued before an intermediate revealing signal also need not remain calibrated conditional on that signal. The reference implementation therefore scores one-step outcomes under the full update history. Products over delayed, overlapping outcomes require a separate conditional-law argument.

These constructions distinguish a calibration alarm, a statistical coverage failure, and an economic adverse event. Each has its own probability allocation. The mathematical contract assumes truthful ordered observations, valid conditional laws, and actual funding facts. Their calibration and institutional provenance remain empirical and operational obligations.

5.5 Defense-in-depth against correlation-model failure

The preceding calculations supply different estimates of the collateral needed for the same portfolio. A required minimum, a stressed scenario loss, and a physical loss forecast can each exceed the fitted correlation charge. The policy below collects the largest active requirement. When a health check fails, it also retains the preceding requirement until a recorded recovery decision. This prevents a failed model update from authorizing an immediate collateral release.

Definition 5.16 (Margin requirements during normal and degraded operation).

At update time t, position \Pi has floor, stress, and physical-risk requirements B_t(\Pi):=\max\{M_t^{\mathrm{floor}}(\Pi),M_t^{\mathrm{stress}}(\Pi),M_t^{\mathrm{cont}}(\Pi)\}. The floor is \sum_i|Q_i|P_i\mu_i^{\mathrm{floor}}, with prescribed minimum rates \mu_i^{\mathrm{floor}}. The stress requirement is the maximum loss over \Omega_0\cup\Omega_{\mathrm{MC}} in Definition 6.24. The physical-risk requirement M_t^{\mathrm{cont}} uses Definition 4.4. The parametric requirement M_t^{\mathrm{param}} uses the margin convention of Definition 3.1 and the linear projection formula in Proposition 3.2. The streaming estimator supplies its return covariance, subject to that proposition’s stated distributional and scaling assumptions.

Let d_t\in\{0,1\} record degraded operation. A failure of model health sets d_t=1. Model health \mathcal H requires a bounded fit condition number, acceptable physical-outcome tail backtests, valid numerical error bounds, and completed tier recalculation. Each numerical bound applies to the law and loss function used by its layer. Proposition 4.12 supplies one such bound under its stated assumptions. A recorded recovery decision clears d_t when \mathcal H holds, with fresh synchronized inputs, completed repricing, and reconciled settlement obligations. Restoring \mathcal H alone does not clear d_t. The requirement is M_{\mathrm{req},t}(\Pi):= \begin{cases} \max\{B_t(\Pi),M_t^{\mathrm{param}}(\Pi)\},&d_t=0,\\ \max\{B_t(\Pi),M_{\mathrm{req},t^-}(\Pi)\},&d_t=1. \end{cases} \tag{27} The preceding requirement belongs to the committed account state and persists across restarts. An unavailable preceding state requires reconstruction before collateral releases resume. Degraded operation halts new risk and collateral withdrawals on affected accounts. Permitted settlement and risk-reducing closure update the funded account ledger. A margin call remains a receivable until payment funds it. An operative legal restriction controls the affected action immediately, independently of statistical health or recovery.

Proposition 5.17 (Layer monotonicity and retained requirements).

Fix the mode and preceding account state. The requirement in (27) is non-decreasing in each active layer and is at least the floor. During degraded operation, M_{\mathrm{req},t}(\Pi)\ge M_{\mathrm{req},t^-}(\Pi). For common nonparametric bound B and estimates p,p_{\mathrm{true}}\ge0, [\max\{B,p_{\mathrm{true}}\}-\max\{B,p\}]_+ \le (p_{\mathrm{true}}-B)_+. \tag{28} In normal operation take B=B_t and p=M_t^{\mathrm{param}}. During degraded operation the current estimate is inactive, so changing it changes neither requirement.

For realized loss \ell_t and funded collateral C_t^{\mathrm{posted}}, the actual shortfall is (\ell_t-C_t^{\mathrm{posted}})_+. If \ell_t=ap, a\ge1, p\ge M^{\mathrm{floor}}, and funded collateral equals \max\{p,M^{\mathrm{stress}},M^{\mathrm{cont}},H\} for retained amount H\ge0, this becomes \left[(a-1)p- \bigl(\max\{M^{\mathrm{stress}},M^{\mathrm{cont}},H\}-p\bigr)_+\right]_+.

Proof. Each active requirement is a maximum of nonnegative amounts. The degraded maximum includes the preceding requirement. For (28), its second maximum is at least B. Subtracting B from the first maximum proves the bound. For the shortfall identity, write \max\{p,M^{\mathrm{stress}},M^{\mathrm{cont}},H\}=p+(\max\{M^{\mathrm{stress}},M^{\mathrm{cont}},H\}-p)_+. Subtract this funded amount from ap and take the positive part. ◻

Remark 5.18 (Historical referent).

Li’s 2000 Gaussian-copula model [58] supplied the correlation-aggregation step in the pricing and rating of CDO tranches in the 2001-2008 period. Its parameters were calibrated on pre-2007 default-correlation samples containing no systemic correlated-default event; when the 2007-2008 housing-default correlation realised at the model’s tail, the tranche valuations and the capital held against them proved insufficient at several dealers [68, 69]. The failure mechanism was reliance on a single model specification rather than the copula choice itself [68]. The referent is valuation, not clearing: credit derivatives were not centrally cleared before 2009. The lesson transfers to a CCP whose margin model takes its correlation input from one estimate, which Definition 5.16 rules out by binding the requirement at the maximum of the four layers; Proposition 5.17 quantifies the resulting bound on parametric-model reliance.

Remark 5.19 (Margin, credit resources, and liquidity).

Participant margin belongs to PFMI Principle 6 and EMIR Article 41 [48, 49]. The stress and floor layers in Definition 5.16 are components of that margin design. The health predicate and retained-margin recurrence support continuing model assessment. Default-fund and dedicated-resource stress tests follow the separate credit construction in Definition 6.2. Currency-specific and deadline-specific liquidity follows Definition 6.6. These calculations require the recorded regime mapping and observed calibration evidence.

6 The Clearing Operator and the Five-Stage Waterfall

We state the CCP’s default-handling procedure as a clearing operator on a set of position accounts: the waterfall of Assumption 2.3(3), defaulter margin, CCP skin-in-the-game, mutualised fund, member socialisation, auto-deleveraging, which follows the EMIR Art. 45 order [49] through socialisation and adds auto-deleveraging. The losses entering the waterfall are fixed at clearing time, so the operator is a deterministic allocation and not a fixed point; this is the contrast with Eisenberg-Noe [1, 2], where each node’s payment depends on the payments it receives. The stages are stated once, as the recursion of §6.2; well-definedness, uniqueness, and order-independence follow.

6.1 Setup

Let [K]:=\{1,\ldots,K\} index accounts. Account k has outstanding obligation o_k\ge0 and outstanding claim c_k\ge0 for this clearing application. These amounts exclude previously discharged obligations and claims. Let G_k\ge0 be its funded collateral balance in the unit of Definition 3.5. Let h_k^{\mathrm{sen}}\ge0 record prior commitments and encumbrances senior to the current settlement loss. These senior obligations are distinct from the obligations represented in o_k-c_k. Define the available collateral and senior funding deficit by C_k:=(G_k-h_k^{\mathrm{sen}})_+, \qquad D_k^{\mathrm{sen}}:=(h_k^{\mathrm{sen}}-G_k)_+, \qquad G_k+D_k^{\mathrm{sen}}=C_k+h_k^{\mathrm{sen}}. An external debit changes G_k and exposes any deficit without erasing senior commitments. An obligation represented in h_k^{\mathrm{sen}} does not also enter this application’s gross loss. The same perimeter applies to gross claims and any permitted netting. If it later becomes the obligation being settled, its reservation and loss entries transfer together under the governing priority rule. For G_k=100, h_k^{\mathrm{sen}}=30, and a separate current loss L_k=90, Stage 1 draws 70 and leaves 20. If a total obligation of 90 instead includes that senior 30, settle the senior part once before applying the remaining-loss waterfall. After an actual senior payment of 30, the remaining funded balance is 70 and the remaining obligation is 60. Its Stage 1 payment leaves zero residual. Write L_k:=(o_k-c_k)_+ for the current loss before available collateral. An account defaults in this application if L_k>C_k. Thus D:=\{k:L_k>C_k\}, s_k:=\min(L_k,C_k), and r_k:=(L_k-C_k)_+. Senior deficits remain distinct unpaid obligations and are outside this application’s residual. They require the governing priority-specific settlement procedure.

Let E_{\mathrm{SIG}} and \mathrm{IF} be the currently drawable balances of the dedicated CCP and insurance pots. Apply their own senior commitments and legal eligibility before computing these amounts. The member, SIG, insurance, and separate-tier pots contain disjoint funded asset quantities. One asset identifier and quantity can supply at most one pot at the same time. A transfer debits its source before crediting its destination. Noncash collateral contributes only its eligible net settlement proceeds under the stated conversion and timing assumptions. A valuation alone does not supply immediate cash liquidity. All balances, priorities, and conversions belong to one committed calculation snapshot. Let \kappa\in(0,1) be the socialisation cap. Let \mathcal{P}:=\{k:c_k>o_k\}, with profit claim \pi_k:=c_k-o_k. Then \mathcal{P}\cap D=\emptyset.

Definition 6.1 (CCP skin-in-the-game tranche).

Let E_{\mathrm{SIG}} \geq 0 denote the CCP’s own equity posted as a dedicated default-management layer, ring-fenced from the mutualised insurance fund \mathrm{IF}. The tranche is consumed in full before any draw on \mathrm{IF}, aligning the CCP’s loss-absorption incentives with members’ (EMIR Art. 45(4); compare the U.S. risk-management standards in Dodd-Frank §5464 [49, 52, 44, 47]). The design choice E_{\mathrm{SIG}} = 0 (“skinless” CCP) is admissible and is discussed in Remark 6.9.

Cover-k asks whether prefunded resources cover the tested simultaneous defaults of up to k member groups. Affiliated members are grouped for default exposure, while legal netting rights still determine which obligations may be offset. A shared market sale can change several members’ recoveries, so losses must be evaluated in a joint scenario.

Definition 6.2 (Joint-scenario Cover-k prefunding).

Fix a committed position, ownership, collateral, and resource snapshot. Let \mathcal G partition clearing members into documented affiliate groups. For an integer k\ge1, define \mathcal D_k:=\left\{\bigcup_{g\in A}g: A\subseteq\mathcal G,\ 1\le |A|\le k\right\}. The stress catalogue \Omega_{\mathrm{stress}} contains historical and prospective joint scenarios. Each scenario includes price moves, collateral deterioration, joint liquidation impact, funding disruption, and provider failures. For D\in\mathcal D_k, let \mathcal N(D) contain its legally enforceable close-out netting sets. For each set n, let L_n(\omega,D) be its jointly simulated close-out loss before collateral. Let C_n(\omega,D) be eligible collateral after stressed conversion costs and prior commitments. Senior liabilities and their backing follow the same clearing-book perimeter as the setup of §6. Define r_n(\omega,D):=[L_n(\omega,D)-C_n(\omega,D)]_+, \qquad R(\omega,D):=\sum_{n\in\mathcal N(D)}r_n(\omega,D). Affiliate aggregation joins default exposure. It creates no additional right to net obligations or transfer collateral. Let E(\omega,D) and F(\omega,D) be stressed eligible values of dedicated CCP resources and the prefunded default fund. They exclude collateral already deducted in C_n. The joint-scenario credit condition is R(\omega,D)\le E(\omega,D)+F(\omega,D) \quad\text{for every }\omega\in\Omega_{\mathrm{stress}},\ D\in\mathcal D_k. \tag{29} The scenario engine evaluates simultaneous close-out from one market state. Assessment receivables, uncalled contributions, and ADL capacity remain separate from these prefunded resources.

Remark 6.3 (Scenario and resource perimeter).

Estimated scenario probabilities support calibration and comparative analysis. A marginal quantile does not replace (29) or automatically exclude a relevant stress. Each resource carries its asset identity, quantity, owner, priority, valuation rule, and permitted use. The same quantity contributes once within a scenario. Client positions remain included when transfer is uncertain [51]. The engine evaluates the simultaneous pool sales and their stressed collateral proceeds. Adding isolated liquidation estimates from unchanged pools can miss joint impact.

Remark 6.4 (Credit and liquidity standards).

PFMI Principle 4 includes participant affiliates in credit stress [48]. Its baseline covers two participants for complex-risk CCPs and CCPs systemically important across jurisdictions, and one for other CCPs. Wider extreme but plausible scenarios remain part of the assessment. Principle 7 treats liquidity separately, by currency and deadline. Its minimum default baseline is one participant with affiliates. The specified complex or cross-jurisdiction CCPs should consider additional two-participant coverage. Participant margin follows Principle 6.

When EMIR applies, Article 42 tests a separate prefunded default-fund floor. Article 43 tests the default fund together with other qualifying prefunded resources against the two largest member exposures. Dedicated CCP resources do not reduce Article 42’s separate floor. Article 44 includes the two largest exposed entities among clearing members or liquidity providers, excluding central banks [50]. It also limits a clearing-member group’s share of required credit lines to 25\%. The recorded regime mapping fixes each member perimeter, affiliate perimeter, resource class, scenario test, and required approval.

Proposition 6.5 (Available-fund sizing specialization).

Assume every relevant prefunded balance remains available in one stable settlement unit throughout the tested scenarios. Let F_{\min}^{\mathrm{policy}}\ge0 be the policy floor. Require \mathcal D_k to include every default combination required by the recorded regime. In particular, use k\ge2 for EMIR Article 43 and the PFMI two-participant credit class. For an additive specialization whose member impacts do not depend on the simultaneous default set, rank member residual exposures as e_{(1)}(\omega)\ge e_{(2)}(\omega)\ge e_{(3)}(\omega), padding missing entries with zero. The Article 42 benchmark is F_{42}^{\mathrm{req}}:=\sup_{\omega\in\Omega_{\mathrm{stress}}} \max\{e_{(1)}(\omega),e_{(2)}(\omega)+e_{(3)}(\omega)\}. For joint liquidation effects, evaluate the corresponding default sets through R(\omega,D) directly. For a regime where that separate floor applies, define \mathrm{IF}_{\min}:= \max\left\{F_{\min}^{\mathrm{policy}},F_{42}^{\mathrm{req}}, \sup_{\omega\in\Omega_{\mathrm{stress}},\,D\in\mathcal D_k} [R(\omega,D)-E(\omega,D)]_+\right\}. For another regime, substitute its applicable separate fund floor. Then \mathrm{IF}\ge\mathrm{IF}_{\min} satisfies the stated credit-resource requirements. With stressed fund assets, evaluate F(\omega,D) directly in (29).

Proof. The last maximum term ensures \mathrm{IF}+E(\omega,D)\ge R(\omega,D) for every tested pair. The first two terms retain the independent policy and default-fund floors. The additive specialization orders the losses within each scenario before taking the scenario supremum. Its proof uses actual availability of the fund balance, as assumed. ◻

The credit test asks whether resources can absorb loss. The liquidity test asks whether the correct currency is available at every payment deadline. The policy below must choose funding actions from information already observed and carry each borrowing’s repayment into later deadlines.

Definition 6.6 (Funded liquidity across currencies and deadlines).

Fix settlement currencies and payment deadlines through the liquidation horizon. A contingency policy \pi selects permitted funding actions from authenticated observations available at the decision time. For scenario \omega, tested default set D, currency c, and deadline \tau, define B_c^\pi(\tau;\omega,D)=B_{c,0}^{\mathrm{usable}} +I_c^{\mathrm{received}}(\tau;\omega,D) +Q_c^\pi(\tau;\omega,D)-O_c^{\mathrm{due}}(\tau;\omega,D). Initial cash excludes prior commitments. The term I_c^{\mathrm{received}} contains receipts available by the deadline. The term Q_c^\pi contains funding proceeds delivered by that deadline. They are disjoint receipt categories. The term O_c^{\mathrm{due}} contains all cumulative payments due, including funding repayments. Require one implementable policy for which B_c^\pi\ge0 at every tested scenario, default set, currency, and deadline. Each funding path records provider survival, draw limits, collateral use, currency, and delivery time. The default family includes material provider failures and their dependencies, with its minimum combinations fixed by the applicable regime. A future receipt supplies no earlier cash. A borrowing adds cash and its repayment obligation, without creating equity. Credit and liquidity calculations share one resource ledger and one consistent scenario path.

Example 6.7 (Joint losses, separate floors, and timing).

Affiliate-group residuals 50+50, 60, and 40 give Cover-1 exposure 100 and Cover-2 exposure 160. Dedicated resources 20 and fund 140 cover the latter, while fund 139 leaves 1. If two members each lose 100 together with probability 0.005, their 99\% marginal loss quantiles are zero. With collateral 10 each, that joint stress still leaves 180 before dedicated resources and the fund. For additive member exposures 100,70,60, combined Cover-2 requires 170 while the separate Article 42 benchmark is 130. Dedicated resources 100 plus fund 70 meet the combined arithmetic and miss the separate fund floor. A payment 100 due at time 1, cash 20, and securities producing 80 at time 2 leave a time-1 liquidity gap of 80. A qualifying facility delivered before time 1 can supply that liquidity, subject to its provider’s stressed survival and repayment schedule.

The allocation needs each surviving account’s available balance and contractual contribution limit. Existing senior commitments reduce availability first. Any further reservation must have a stated priority relative to loss collection and socialisation. Socialisation is the allocation of remaining loss to surviving members under those caps.

Definition 6.8 (Waterfall clearing vector).

For k \notin D let w_k := |Q_k| P_k be account k’s position notional, and let \mathcal{B}:= \{k \notin D : w_k > 0\} be the socialisation base, the non-defaulting accounts with an open position; a pro-rata rule in notional socialises nothing to an account that holds collateral and no position. The balance C_k already excludes commitments senior to Stage 1. Let \widetilde b_k\ge0 be an additional reservation subordinate to Stage 1 and senior to socialisation. Its recorded governing priority must permit that ordering. After Stage 1, its funded portion and deficit are b_k:=\min\{\widetilde b_k,C_k-s_k\},\qquad D_k^b:=(\widetilde b_k-C_k+s_k)_+. The reservation claim remains \widetilde b_k=b_k+D_k^b. Its deficit remains separate from the current clearing residual. Thus 0\le b_k\le C_k-s_k describes a funded subordinate reservation. A pre-existing senior commitment belongs in h_k^{\mathrm{sen}}, before Stage 1. Define F_k:=C_k-s_k-b_k,\qquad a_k:= \begin{cases} \min\{\kappa C_k,F_k\},&k\in\mathcal{B},\\ 0,&k\notin\mathcal{B}. \end{cases} Thus a_k respects both the contractual cap and the remaining funded balance. An unfunded maintenance requirement is a separate shortfall. A waterfall clearing vector is a tuple (\mathbf{s}, e, d, \boldsymbol{\ell}, \boldsymbol{\delta}) with

  • \mathbf{s} \in \mathbb{R}_{\geq 0}^K the seizure vector, s_k = \min(L_k, C_k) for every k;

  • e \in [0, E_{\mathrm{SIG}}] the skin-in-the-game draw and d \in [0, \mathrm{IF}] the fund draw;

  • \boldsymbol{\ell} \in \mathbb{R}_{\geq 0}^K the socialisation vector, \ell_k = 0 for k \notin \mathcal{B} and \ell_k = \min(t\, w_k, a_k) for k \in \mathcal{B}, for one common t \geq 0 (pro rata with per-account cap);

  • \boldsymbol{\delta} \in \mathbb{R}_{\geq 0}^K the ADL allocation, \delta_k = 0 for k \notin \mathcal{P} and \delta_k = u\, \pi_k for k \in \mathcal{P}, for one common u \in [0, 1] (pro rata in unrealised profit);

whose residual \Delta^{\mathrm{res}} \;:=\; \sum_k L_k - \sum_k s_k - e - d - \sum_k \ell_k - \sum_k \delta_k \tag{30} is non-negative, and which satisfies the exhaustion priorities: a later stage is positive only if every earlier stage’s available amount is exhausted, and the residual is positive only if every available amount is exhausted. Explicitly, \begin{align*} d > 0 &\Rightarrow e = E_{\mathrm{SIG}},\\ \textstyle\sum_k \ell_k > 0 &\Rightarrow e = E_{\mathrm{SIG}},\quad d = \mathrm{IF},\\ \textstyle\sum_k \delta_k > 0 &\Rightarrow \left\{ \begin{aligned} e&=E_{\mathrm{SIG}}, & d&=\mathrm{IF},\\ \ell_k&=a_k &&(k\in\mathcal{B}), \end{aligned} \right.\\ \Delta^{\mathrm{res}} > 0 &\Rightarrow \left\{ \begin{aligned} e&=E_{\mathrm{SIG}}, & d&=\mathrm{IF},\\ \ell_k&=a_k &&(k\in\mathcal{B}),\\ \delta_k&=\pi_k &&(k\in\mathcal{P}). \end{aligned} \right. \end{align*} Each implication names every earlier stage, including a stage whose available amount is zero. Stage 1 collects each current loss from available account collateral, after senior commitments. Its fixed collection carries no further priority clause. Stages 1-4 follow the EMIR Art. 45 order (defaulter resources, dedicated own resources, mutualised resources) [49]; Stage 5, auto-deleveraging, is a derivative-venue addition with no EMIR counterpart.

Remark 6.9 (Skinless design).

Setting E_{\mathrm{SIG}} = 0 reduces Definition 6.8 to a four-stage waterfall without CCP first-loss. The trade-off is studied in [6, 47]: positive SIG aligns the CCP’s incentives with those of members at the cost of CCP-equity commitment, and a skinless CCP externalises first-loss to the mutualised fund. EMIR Art. 45(4) mandates dedicated own resources before mutualised member contributions for EU CCPs [49]. Dodd-Frank §5464 instead establishes U.S. risk-management standards for designated financial market utilities [52]; it does not specify the same tranche.

6.2 Stage structure

The five stages of Definition 6.8 are the following recursion.

Stage 1: Loss settlement and defaulter margin seizure. Deduct senior commitments before calculating C_k=(G_k-h_k^{\mathrm{sen}})_+. The clearinghouse collects s_k=\min(L_k,C_k) from every account with a current gross loss. The accounts with L_k>C_k default, and their remaining shortfall enters the post-collateral waterfall. The AMM-price-impact kernel values any permitted non-settlement collateral. Residual: \Delta_1:=\sum_k(L_k-s_k)_+.

Stage 2: CCP skin-in-the-game. e = \min(\Delta_1, E_{\mathrm{SIG}}) is drawn against the CCP’s dedicated tranche (Definition 6.1). Residual: \Delta_2 := (\Delta_1 - e)_+.

Stage 3: Insurance fund draw. d = \min(\Delta_2, \mathrm{IF}). Each draw atomically consumes the current eligible funded balance. Block-end reconciliation checks the resulting ledger and cannot authorise reuse within the block. Residual: \Delta_3 := (\Delta_2 - d)_+.

Stage 4: Capped socialisation. The target \Delta_3^{\mathrm{soc}} := \min(\Delta_3, \sum_{k \in \mathcal{B}} a_k) is allocated across the socialisation base by the pro-rata rule of Definition 6.8, with the common multiplier chosen to place the target: \ell_k \;=\; \min\bigl(t^*\, w_k,\; a_k\bigr) \ \ (k \in \mathcal{B}), \qquad t^* \;:=\; \inf\Bigl\{t \geq 0 \,:\, \textstyle\sum_{k \in \mathcal{B}} \min(t\, w_k,\, a_k) \geq \Delta_3^{\mathrm{soc}}\Bigr\}. \tag{31} This closed form equals the familiar iterative scheme (allocate pro rata, cap the binders, redistribute over the active set until the residual is placed or every cap binds). Residual: \Delta_4 := \Delta_3 - \sum_k \ell_k.

Stage 5: Auto-deleveraging (ADL). Profitable positions are reduced proportionally to unrealised profit: \delta_k = \pi_k \cdot \min(\Delta_4, \sum_{k' \in \mathcal{P}} \pi_{k'})/\sum_{k' \in \mathcal{P}} \pi_{k'} for k \in \mathcal{P}, with \delta_k = 0 for k \notin \mathcal{P} and for every k when \mathcal{P}= \emptyset, so that no division by zero occurs. The terminal residual is \Delta^{\mathrm{res}} := (\Delta_4 - \sum_{k' \in \mathcal{P}}\pi_{k'})_+.

Remark 6.10 (Re-margining and funding clocks).

The CCP can recompute margin on each clearing step. That computation records an amount due. It does not show that the settlement asset has arrived. The funding clock ends only when the named provider and rail give the transfer finality under their rules. Fedwire, for example, derives finality from Regulation J and Operating Circular 6 [34]. A cross-border route can also contain message, compliance, funding, and beneficiary-credit intervals after the margin calculation [35, 28]. The CCP must state the payment deadline and the position treatment while funding is pending.

Remark 6.11 (Funded pots and outstanding claims).

Index disjoint funded pots by j and write their actual balances as B_j\ge0. Let R_j be pending payment commitments and E_j other prior encumbrances, with disjoint obligation identifiers. The free capacity F_j and commitment deficit D_j satisfy F_j:=(B_j-R_j-E_j)_+, \qquad D_j:=(R_j+E_j-B_j)_+, \qquad B_j+D_j=F_j+R_j+E_j. New cash commitments draw only from F_j. An external debit reduces B_j and recomputes F_j,D_j, retaining the commitments. Execution of a reserved payment requires both its legal authority and actual funded cash. It consumes that payment’s reservation and the cash once. The account balance C_k is the capacity remaining after commitments senior to its Stage 1 loss. SIG and insurance draws use their corresponding available capacities.

Define the total funded book and outstanding ADL-eligible claim book by A(t):=\sum_jB_j(t),\qquad U(t):=\sum_{k\in\mathcal{P}(t)}\pi_k(t),\qquad \mathcal{C}^{\mathrm{book}}(t):=A(t)+U(t). \tag{32} The funded book includes reserved balances. It therefore need not equal the immediately drawable waterfall capacity. The claim book U is an outstanding liability that ADL can extinguish. It supplies no cash.

Let P(t) be cumulative actual cash debits at Stages 1–4 and H(t) cumulative ADL claim reductions. Let R(t) record the part of those payments actually credited to pots counted in A, so 0\le R(t)\le P(t). Let F_A,F_U be net external flows and M_A,M_U valuation changes in the two books. Every flow is recorded once, with its funded or claim type. An assessed call or restitution claim enters a receivable book until paid. It does not enter A. Assume each cash unit paid reduces an outstanding claim already included in U by exactly one unit. The payment record identifies that claim and its book membership. Then \begin{align*} A(t)&=A(0)-P(t)+R(t)+F_A(t)+M_A(t), \tag{33} \\ U(t)&=U(0)-P(t)-H(t)+F_U(t)+M_U(t). \tag{34} \end{align*} Historical receipt attribution identifies the obligation discharged by a payment. That attribution persists after the recipient spends the credited cash. It neither proves a current funded balance nor debits the source a second time. Any later spending is its own actual flow in the funded ledger. For payments outside U, or a different claim-discharge amount, replace P in the second identity by the actual reduction of claims in U. Then the following par-settlement bound requires a separate argument.

Under the par convention, writing F:=F_A+F_U and M:=M_A+M_U gives \mathcal{C}^{\mathrm{book}}(t) =\mathcal{C}^{\mathrm{book}}(0)-2P(t)-H(t)+R(t)+F(t)+M(t). \tag{35} The two cash-payment terms remove one resource and discharge one claim. At fixed marks with no external flows, nonnegative books and R\le P imply P(t)+H(t)\le\mathcal{C}^{\mathrm{book}}(0). \tag{36} This bounds cumulative loss absorption under the stated flow assumptions. Senior deficits and the terminal clearing residual remain unpaid obligations. They add no funded resources and extinguish no claims automatically.

The recursion has one allocation choice requiring care: capped proportional contributions from surviving accounts. As the common multiplier rises, uncapped accounts contribute more until the required total is met. The next proof establishes that the resulting allocation is unique even when several multiplier values describe fully capped accounts.

6.3 Existence, uniqueness, and order-independence

Theorem 6.12 (The waterfall is a well-defined clearing operator).

Fix obligations, funded balances, legal priorities, senior commitments, subordinate reservations, surviving-member weights, SIG capacity, insurance capacity, and \kappa\in(0,1). There is exactly one waterfall clearing vector (\mathbf{s}^*,e^*,d^*,\boldsymbol{\ell}^*,\boldsymbol{\delta}^*). It is the output of the stage recursion of §6.2. Each account satisfies 0\le\ell_k\le a_k,\qquad s_k+\ell_k+b_k\le C_k, \qquad s_k+\ell_k+b_k+h_k^{\mathrm{sen}}\le G_k+D_k^{\mathrm{sen}}. Its residual is the loss beyond the combined loss-absorption limit, \Delta^{\mathrm{res}} \;=\; \Bigl(\textstyle\sum_k (L_k - C_k)_+ \;-\; E_{\mathrm{SIG}} \;-\; \mathrm{IF} \;-\; \sum_{k \in \mathcal{B}} a_k \;-\; \sum_{k \in \mathcal{P}} \pi_k\Bigr)_+ , \tag{37} so \Delta^{\mathrm{res}} = 0 iff the losses beyond defaulter collateral do not exceed the combined amounts available at Stages 2–5, \sum_k (L_k - C_k)_+ \leq E_{\mathrm{SIG}} + \mathrm{IF} + \sum_{k \in \mathcal{B}} a_k + \sum_{k \in \mathcal{P}}\pi_k. The statement is about a deterministic allocation: L_k = (o_k - c_k)_+ is fixed at clearing time, no payment depends on payments received, and there is no fixed point to solve for, in contrast with Eisenberg-Noe [1].

Proof. Existence. The recursion of §6.2 produces a tuple of the required form: seizure is full, e = \min(\Delta_1, E_{\mathrm{SIG}}), d = \min(\Delta_2, \mathrm{IF}), socialisation is \min(t^* w_k, a_k) with t^* from (31), ADL is pro rata in profit, and each stage draws only what the previous stages left, so the exhaustion priorities hold and the residual is (37). For t^*: \varphi(t) := \sum_{k \in \mathcal{B}}\min(t w_k, a_k) is continuous, non-decreasing, piecewise linear, with \varphi(0) = 0 and, since w_k > 0 on \mathcal{B}, \varphi(T)=\sum_{k\in\mathcal{B}}a_k at finite T=\max_{k\in\mathcal{B}}a_k/w_k. For an empty base take T=t^*=0. Continuity gives attainment. Finally \ell_k\le a_k\le C_k-s_k-b_k proves the available-balance inequality. Substitute C_k=G_k+D_k^{\mathrm{sen}}-h_k^{\mathrm{sen}} for the second inequality. If D_k^{\mathrm{sen}}>0, then C_k=0 and this account supplies no cash draw. Disjoint pots prevent reuse of the same funded quantity at later stages.

Uniqueness. Let (\mathbf{s}, e, d, \boldsymbol\ell, \boldsymbol\delta) satisfy Definition 6.8. Seizure is fixed. If e < E_{\mathrm{SIG}} then d = 0, \boldsymbol\ell = 0, \boldsymbol\delta = 0 by the priorities, so \Delta^{\mathrm{res}} = \Delta_1 - e, which is positive unless e = \Delta_1, and a positive residual forces e = E_{\mathrm{SIG}}, a contradiction; hence e = \min(\Delta_1, E_{\mathrm{SIG}}). The same argument gives d = \min(\Delta_2, \mathrm{IF}), then \sum_k \ell_k = \Delta_3^{\mathrm{soc}}, then \sum_k \delta_k = \min(\Delta_4, \sum_{\mathcal{P}}\pi_k); the pro-rata rule fixes the ADL allocation from its sum. For socialisation the common multiplier fixes the allocation from its sum: if t_1 < t_2 both give \varphi(t_i) = \Delta_3^{\mathrm{soc}} then, since \varphi is strictly increasing wherever some account of \mathcal{B} is uncapped, every account of \mathcal{B} is capped already at t_1, and \min(t_1 w_k, a_k) = \min(t_2 w_k, a_k) for all k. ◻

Proposition 6.13 (Order-independence under simultaneous defaults).

Let D be the set of accounts defaulting at a single clearing time. Processing the accounts of D in any order yields the clearing vector of Theorem 6.12, provided the stages are applied level by level: all seizures before any SIG draw, all SIG draws before any fund draw, all fund draws before any socialisation, all socialisation before any ADL.

Proof. Under level-by-level application each stage’s input is an aggregate: \sum_{k \in D} s_k^* is a sum of per-account terms, e^* and d^* depend on \Delta_1 and \Delta_2 only, the socialisation allocation depends on \Delta_3 and \{w_{k'},a_{k'}\}_{k'\in\mathcal{B}} only, and ADL on \Delta_4 and \{\pi_k\} only; so the output is the unique vector of Theorem 6.12 whatever the order. Applying the stages per account across levels would make a later account’s socialisation depend on an earlier account’s draws, and the output would depend on the order. ◻

A calculated zero residual records a complete loss allocation under the fixed inputs. To turn that allocation into discharged obligations, the system also needs a legal netting foundation and evidence of final transfers. Delivery-versus-payment links the release of an asset claim to completion of the corresponding payment.

6.4 Netting foundation and settlement gate

Arithmetic can form a fixed obligation vector under several legal foundations. Their consequences differ. Novation replaces an existing contract with obligations to the central counterparty. An open-offer arrangement makes the central counterparty a party when a qualifying trade is formed under its rules.

(a)

With no netting agreement, the operator uses the gross loss vector.

(b)

An enforceable multilateral netting agreement without interposition can create net obligations among the participants. It does not create a CCP, a skin-in-the-game tranche, a default fund, mutualisation, or auto-deleveraging.

(c)

CCP interposition through novation or open offer makes the CCP the counterparty and supplies the legal basis for the five-stage waterfall.

The arithmetic that forms a fixed vector does not require interposition. The waterfall in this paper does. A claim pack must declare its netting foundation before the operator is applied. Admissible Obligation Transitions defines that declaration and the at-most-once consumption rule for each claim [39]. This paper develops the consequences across claims. The comparison between bilateral and centrally cleared exposure follows Duffie and Zhu [43].

A settlement gate releases matched internal claim transitions only after each required leg presents authenticated completion evidence. Linked delivery-versus-payment makes those internal releases conditional on one another, consistent with PFMI Principle 12 [48]. It does not make independent external systems atomic. It does not give an external leg legal finality or replace its provider’s rulebook. Op: A Typed Bytecode for Compliance-Carrying Operations defines provider finality for each leg [38]. Event-Collect BFT defines ledger confirmation [40]. A unique, order-independent clearing vector can therefore exist before legal discharge. Discharge still requires an enforceable netting basis and final transfers under the applicable systems.

Remark 6.14 (AMM-price-impact gives deterministic C_k adjustment).

In Eisenberg-Noe each node’s outside endowment is exogenous. Here an executed collateral sale contributes its net settlement proceeds to G_k, and hence to C_k after senior commitments. Under Assumption 2.1(2), the curve proceeds follow exactly from the committed reserves and sale quantities. Fees and separately identified conversion costs reduce those proceeds once. The same sale’s impact remains in this recovery entry when the waterfall uses C_k. Scenario comparisons specify a separate eligible recovery for each route under Definition 6.16.

6.5 Porting of client positions

Standard CCP rules permit client positions to move to a surviving member after default (EMIR Art. 48; PFMI Principles 13 and 14 [49, 48]). In the AMM-CCP setting, a client position decomposes into pool-share claims and derivative bookings against surviving counterparties, so porting is structurally more granular than the traditional single-member carry-over.

Porting can avoid an immediate sale by moving an accepted position and its associated obligations to a surviving member. Its benefit depends on what is actually transferred, paid, or discharged. The comparison below therefore gives each candidate route a complete ledger with the same initial claims and deadlines.

Definition 6.15 (Portable position).

Let k denote a clearing member with client accounts \{j : \mathrm{parent}(j) = k\}. Client j’s position has two components. Its reserve-share component is the claim \alpha_j \in \mathbb{R}_{\geq 0} on each pool i, the share of pool reserves attributable to j. Its booked component is the vector (Q_j^p,S_j) of perpetual and event positions. Either component is portable only when a surviving member k' accepts the corresponding reserve claim or books the transferred position.

Definition 6.16 (Common valuation basis for default routes).

Fix a valuation time, settlement numeraire, payment deadline, original claims, ownership records, and enforceable netting sets. A route r specifies the accepted transfers, remaining obligations, asset sales, fees, funding sources, senior commitments, and their deadlines. For each affected netting set k, let L_k^r be its remaining loss after the route’s legally effective transfers and discharges. Let G_k^r be its funded settlement balance at the required deadline, and put C_k^r=(G_k^r-h_k^{\mathrm{sen},r})_+. The post-collateral loss is R(r)=\sum_k(L_k^r-C_k^r)_+. Every cash-flow occurrence enters its owner’s route ledger once. Net sale proceeds include impact and fees. A separate position unwind enters the remaining loss through its own cash-flow entries. A ported asset keeps its recipient, encumbrances, and associated obligations. An accepted in-kind discharge reduces L_k^r by its agreed discharge amount. A replacement cash payment increases G_k^r only when its funding and deadline are established. A quoted mark alone supplies neither transition. Mutually exclusive routes share the initial snapshot and use separate ledgers.

Proposition 6.17 (Porting versus liquidation).

Fix an allocation a of portable positions to surviving members. Assume the required authority, recipient acceptance, and route funding are established under Definition 6.16.

For each surviving member k', let \Delta M_{k'}^{\mathrm{port}}(D;a) be its incremental margin after accepting its assigned positions. Let C^{\mathrm{slack}}_{k'} be its eligible collateral capacity above maintenance before the transfer. Full porting meets these member margin constraints exactly when \Delta M_{k'}^{\mathrm{port}}(D;a)\leq C^{\mathrm{slack}}_{k'} \qquad\text{for every surviving member }k'. \tag{38}

The losses presented to the post-collateral waterfall are \mathrm{Liq}(D)=R(\mathrm{liq}), \qquad \mathrm{Port}(D;a)=R(\mathrm{port},a). Their difference uses the same original claims and accounting perimeter. In the special case L_k^{\mathrm{liq}}=L_k^{\mathrm{port}}=L_k and C_k^{\mathrm{liq}}=C_k^{\mathrm{port}}-s_k\geq0 with s_k\geq0, it is \mathrm{Liq}(D)-\mathrm{Port}(D;a) =\sum_k\left[(L_k-C_k^{\mathrm{port}}+s_k)_+-(L_k-C_k^{\mathrm{port}})_+\right]. \tag{39} Each summand lies in [0,s_k]. It equals s_k when L_k\geq C_k^{\mathrm{port}}, and zero when L_k\leq C_k^{\mathrm{port}}-s_k. Between these cases it equals L_k-C_k^{\mathrm{port}}+s_k. Thus avoided slippage equals the reduction in waterfall loss when every affected loss already exhausts the port route’s eligible collateral. Changes to liabilities, timing, fees, or funding use the general route difference above.

Proof. The route ledger determines each remaining loss and eligible balance before the waterfall applies its Stage 1 minimum. Consequently the remaining loss is (L_k^r-C_k^r)_+ for each netting set. Subtract the two route sums. Under the special-case assumptions, substitution gives (39). For u=L_k-C_k^{\mathrm{port}}, the expression (u+s_k)_+-u_+ is s_k, zero, or u+s_k on the three stated intervals. The member margin conditions follow by comparing each assigned risk increment with that member’s eligible slack. Slack preserves the receiving member’s margin and remains separate from payment of the default loss. ◻

Example 6.18 (One impact deduction and one funded alternative).

Let a netting set owe 100 and hold collateral with pre-sale mark 80. The liquidation route recovers 70 after impact, so its residual is 30. Suppose an accepted port route supplies a funded settlement payment of 80 against the transferred assets and positions. Its residual is 20, and the route benefit is 10. The liquidation balance already contains the impact deduction. Adding another 10 to its residual would charge that deduction twice. With loss 75 instead, the same funded alternatives give residuals 5 and zero, so the benefit is 5. The unused portion of the avoided impact increases the estate’s retained balance. Recipient acceptance of a marked asset without the stated payment requires its own remaining-obligation ledger before this comparison applies.

Remark 6.19 (Porting under hub-asset concentration).

When all surviving members are exposed to the same hub asset M, their collateral slack falls together with the hub price. A full port can then violate (38) for every allocation even when aggregate slack appears sufficient. A feasible route presents its own remaining loss R(\mathrm{port},a) to the waterfall. Its benefit follows from the route comparison, including funding, timing, and the clipped recovery effect in (39). Collateral held in the settlement asset (Definition 11.1) removes the hub-price dependence of surviving members’ collateral, though not of their position marks.

Charging a survivor can leave that account unable to meet its next maintenance requirement. The following cascade repeats the waterfall for these newly defaulting accounts while keeping market prices fixed. Each processed account leaves the active set, which supplies the finite bound on the number of rounds.

Definition 6.20 (Discrete default cascade).

Let \mathcal{A}_1=[K] be the active accounts and let D_1\subseteq\mathcal{A}_1 be the initial non-empty default set. In round n, the waterfall processes the aggregate loss of D_n once and removes those accounts, so \mathcal{A}_{n+1}=\mathcal{A}_n\setminus D_n. Stage 4 debits and any settlement recredits are posted before the next maintenance test. The next set D_{n+1} contains exactly the accounts in \mathcal{A}_{n+1} that the net round-n update puts into default. A processed account never re-enters the active set. Marks stay fixed, and no deposit, withdrawal, fee accrual, membership transfer, or other external flow occurs between rounds. The cascade stops when the next default set is empty.

This discrete cascade is distinct from the continuous price-liquidity feedback of Section 9, which we call the reflexive cascade.

Corollary 6.21 (Default-cascade termination and cumulative absorption).

Let \{D_n\}_{n \geq 1} be a discrete default cascade in the sense of Definition 6.20. Assume each cash payout reduces a claim already included in U by the same amount, as in Remark 6.11. Then:

(i)

Cumulative loss bound. Write P_n for the cash transferred at Stages 1–4 in round n, H_n for the profit extinguished by ADL, and \Delta_n^{(\mathrm{abs})}:=P_n+H_n. Then \sum_{n \geq 1} \Delta_n^{(\mathrm{abs})} \;\leq\; A(0)+\sum_{k\in\mathcal{P}_0}\pi_k^{(0)}, \tag{40} where A(0) is the total initial funded book in (32). If every funded pot is initially available, this equals \sum_kC_k^{(0)}+E_{\mathrm{SIG},0}+\mathrm{IF}_0. For an account receiving no payment, cumulative socialisation over n rounds is at most [1-(1-\kappa)^n]G_k^{(0)}. If senior commitments remain fixed or increase, replace G_k^{(0)} by the sharper available balance C_k^{(0)}.

(ii)
Finite termination. The cascade terminates after at most K rounds with a non-empty defaulter set.

Proof. (i) Apply (35) after N rounds. Here P=\sum_{n\leq N}P_n, H=\sum_{n\leq N}H_n, F=M=0, and the cumulative recipient recredit satisfies 0\leq R\leq P. Since \mathcal{C}^{\mathrm{book}}(N)\geq0, \sum_{n\leq N}\Delta_n^{(\mathrm{abs})}=P+H \leq 2P+H-R \leq \mathcal{C}^{\mathrm{book}}(0). Letting N increase proves (40). Let S_n be cumulative socialisation from an account receiving no payment. Its remaining funded balance is at most G_k^{(0)}-S_n. Thus S_{n+1}\le S_n+\kappa(G_k^{(0)}-S_n). Induction gives the stated geometric bound. Fixed or increasing senior commitments give the same recurrence with initial available balance C_k^{(0)}. Releasing a prior commitment can increase availability without adding new funding, which requires the gross-balance bound.

(ii) By Definition 6.20, a non-terminal round has D_n\neq\emptyset and removes D_n from the active set. The sets D_n are therefore pairwise disjoint. Since \mathcal{A}_1=[K], their cardinalities satisfy \sum_n|D_n|\leq K. Hence at most K non-terminal rounds occur. The bound follows from removal of accounts, not from a lower bound on loss per round. ◻

Remark 6.22 (Cascade depth is buffer-distribution dependent).

Corollary 6.21 bounds the cumulative absorbed obligation. The number of rounds cannot be derived from the socialisation cap \kappa alone. The cascade depth depends on the joint distribution of post-Stage-4 margin buffers across counterparties: when all counterparties have post-socialisation margin above maintenance, the cascade terminates in one round. A sharp bound on cascade depth requires a distributional assumption on the buffer density; we leave this as Open Problem 7.

6.6 Stress scenario framework

The cumulative absorption bound of Corollary 6.21 is evaluated against a scenario distribution. PFMI Principle 4 [48] and EMIR Art. 49 [49] require CCPs to stress the waterfall against extreme but plausible events; Definition 6.2 evaluates simultaneous affiliate-group defaults across the recorded joint scenarios. Liquidity has the separate currency and deadline test of Definition 6.6. We fix the minimal scenario template used throughout the paper.

Definition 6.23 (Stress scenario).

A stress scenario \omega = (\boldsymbol\Delta P, \boldsymbol\delta, \boldsymbol{\Delta R_{\!B}}, \mathbf P^\omega) is a tuple specifying: (i) a joint price shock \boldsymbol\Delta P \in \mathbb{R}^N on spoke assets; (ii) settlement-asset depeg magnitudes \boldsymbol\delta \in [0,1]^{|\mathcal{S}|}; (iii) pool-depth shocks \boldsymbol{\Delta R_{\!B}} \in \mathbb{R}_{\leq 0}^N; and (iv) a positive-semidefinite correlation matrix \mathbf P^\omega \in \mathcal P_{\mathrm{stress}}(\mathbf m) from Definition 3.12. The fourth coordinate is a whole dependence scenario, not a scalar upward shift. Lower correlation is conservative for opposite-signed legs; higher correlation is conservative for same-signed legs. The joint distribution \pi(\omega) is characterised by a marginal-plus-copula specification; the copula family, marginals, and parameters are fixed calibration inputs. The catalogue also records affiliate defaults, provider dependencies, collateral access, cash-flow timing, and simultaneous close-out. Probabilities support comparative risk estimates while each required joint scenario retains its credit and liquidity test.

Definition 6.24 (Scenario catalogue).

The minimal catalogue \Omega_0 fixes six event classes and the scenario coordinates each one stresses, with magnitudes calibrated from the source series before use and rescaled to current spoke and hub exposures: (H1) a single-day broad-market crash of the October 1987 type (\boldsymbol\Delta P); (H2) a multi-day cross-asset credit freeze with basis widening and funding withdrawal of the September 2008 type (\boldsymbol\Delta P, \boldsymbol{\Delta R_{\!B}}, \mathbf P^\omega); (H3) a pandemic liquidity shock with elevated stablecoin-depeg probability of the March 2020 type (\boldsymbol\Delta P, \boldsymbol\delta); (H4) the full depeg of an endogenous settlement asset with a signed-book correlation scenario, May 2022 (\boldsymbol\delta, \mathbf P^\omega); (H5) the one-day reflexive collapse of a fractionally backed algorithmic asset, June 2021 (\boldsymbol\Delta P, \boldsymbol{\Delta R_{\!B}}); and (H6) a reserve-bank closure with a temporary issuer-backed stablecoin depeg of the March 2023 type (\boldsymbol\delta, \mathbf P^\omega) [35]. \Omega_0 is supplemented by a Monte Carlo envelope \Omega_{\mathrm{MC}} drawn from the worst q=10^{-3} probability mass under the marginal-plus-copula law of Definition 6.23.

Remark 6.25 (Reverse stress testing).

Reverse stress testing inverts the direction: given a residual shortfall threshold \bar\Delta > 0, identify the minimum scenario under which \Delta^{\mathrm{res}}(\omega) \geq \bar\Delta. One admissible objective is a weighted norm on (\boldsymbol\Delta P, \boldsymbol\delta, \boldsymbol{\Delta R_{\!B}}) plus \|\mathbf P^\omega-\mathbf P^{\mathrm{base}}\|_{\mathrm F}, subject to \mathbf P^\omega\succeq0 and unit diagonal. The scenario template of Definition 6.23 makes this inversion a finite-dimensional constrained optimisation. Evaluation against a live book requires specified positions and lies outside the model.

7 Compliance-Tier-Dependent Margin

A CCP clearing instruments whose compliance state varies across investor classes faces margin-state transitions that the return-correlation structure alone cannot capture. One Entity in Many Jurisdictions defines the composed standing and lawful holder set used here [37]. An instrument compliant for all investors has a different liquidity and hedging profile than one restricted to a gated pool of eligible investors, and a tier transition changes the margin requirement instantaneously, independently of any price or correlation move. This section states the transition protocol and the sign of the margin delta; the breach-response protocol that consumes it is Appendix B.

7.1 Instrument tiers and gated pools

A tier is a model label for the book in which the applicable rules permit a position to trade. The Cold, Warm, and Hot labels below distinguish restricted issuance, a restricted trading pool, and the main clearing book. They classify stated eligibility. Their names establish no legal permission on their own.

Definition 7.1 (Instrument compliance tier).

Each instrument I at clearing time t carries a compliance tier \tau_I(t) \in \{\mathrm{Cold}, \mathrm{Warm}, \mathrm{Hot}\} drawn from the instrument’s composed compliance state across all applicable jurisdictional domains. Informally:

  • \mathrm{Cold}: open to issuance and still uncleared for public secondary trade; held in a restricted book.

  • \mathrm{Warm}: cleared for a gated pool of eligible investors (qualified by compliance-domain constraints); positions are isolated to the gated pool with separate margin and default capacity.

  • \mathrm{Hot}: fully compliant across all applicable domains; cleared into the main book with the margin framework of §3 and the waterfall of §6.

Definition 7.2 (Gated-pool margin floor).

A Warm-tier instrument held in the gated pool carries a margin floor \mu_I^{\mathrm{Warm-floor}} \;:=\; \max(\mu_I^{\mathrm{floor}},\, \mu^{\mathrm{gated}}), \tag{41} where \mu^{\mathrm{gated}} > \mu_I^{\mathrm{floor}} is a protocol-set conservative floor reflecting the reduced hedge-book depth available in the gated pool relative to the main book. Warm-tier positions do not inherit correlation credits from cross-pool positions in the main book.

7.2 Tier-transition recalculation protocol

Definition 7.3 (Tier-transition margin recalculation).

Let I be an instrument with current tier \tau_I(t^-) and new tier \tau_I(t^+) following a compliance-state change at time t. The CCP re-margins positions in I atomically at time t per the tier-transition matrix of Table 1.

A margin calculation can remain numerically correct after an operative legal event changes which action is permitted. A dispatch sends an authorized action to its execution provider. The legal-event generation is a counter recording changes to the applicable event state. Checking that counter and committing the action together prevents a decision from using a stale observed rule.

Definition 7.4 (Legal-event precedence).

A legal event records its issuing authority, affected instrument and actions, effective time, observed time, and applicable rule. The configured rule interpreter validates authority, instrument scope, and precedence. It orders operative rules by effective time and governing precedence, rather than callback arrival. Let \mathrm{Legal}_t(a) be the resulting eligibility predicate for action a. Future events activate at their effective time. Authenticated admission, scheduled activation, repeal, and replacement each advance the legal-event generation. An authenticated event observed after its effective time updates this predicate before the next local action dispatch. Economic dwell times, disclosure schedules, and model recovery cannot postpone that update. Each dispatch validates the latest legal-event generation and commits against that generation atomically. A changed generation requires recomputation before dispatch. The system automatically executes eligible funding, settlement, closure, and porting actions under the current rule. Repeal and replacement events use the same authority and effective-time rules. This local guarantee begins at authenticated observation. The effective-to-observed interval is recorded separately. Previously dispatched external actions follow the provider’s cancellation and finality rules. Their actual receipts remain attributable to the original command and obligation after a generation change. The event schema and provider rules are required deployment inputs.

Table 1. Tier-transition margin recalculation matrix. Each transition supplies recalculated tier requirements. During degraded operation, equation (27) retains the preceding requirement and applies increases before subsequent position changes. Pool direction alone does not determine the sign of the total margin change.
Transition Margin formula Pool handling Halt condition
Cold \to Warm M^{\mathrm{cross}}_{\mathrm{gated}} at \mu^{\mathrm{Warm-floor}} To gated pool None
Warm \to Cold M^{\mathrm{iso}} at \mu^{\mathrm{Cold-floor}} \geq \mu^{\mathrm{Warm-floor}} Freeze Stop new opens
Warm \to Hot M^{\mathrm{req}}(\Pi), Definition 5.16 To main book None
Hot \to Warm M^{\mathrm{cross}}_{\mathrm{gated}} at \mu^{\mathrm{Warm-floor}} To gated pool; drain credits Stop new opens
Hot \to Cold M^{\mathrm{iso}} at \mu^{\mathrm{Cold-floor}} Freeze, liquidate Revoke market making

Remark 7.5 (Sign of the margin delta).

Write \Delta M:=M^{\mathrm{new}}(\Pi_I)-M^{\mathrm{old}}(\Pi_I). Its sign follows only from a pointwise comparison of the two complete margin formulas. Warm \to Cold has \Delta M\geq0 when the stated Cold floor dominates the gated formula for the actual position; Cold \to Warm has the reverse sign under the converse comparison. Hot \leftrightarrow Warm has no universal sign. Moving to Warm removes main-book correlation credits, but the Hot requirement may already bind at a larger stress charge. Hot \leftrightarrow Cold likewise requires an explicit comparison with M^{\mathrm{req}}. A lost credit is non-negative, but it does not determine the sign of the total change by itself.

Remark 7.6 (Health-predicate interaction).

The health predicate \mathcal{H} of Definition 5.16 includes “no compliance-tier transition in flight on any leg” to prevent margin-recalculation race conditions: during tier recalculation, the current parametric estimate becomes inactive and the preceding requirement remains effective. New-position opening on the affected leg is halted. The atomic re-margin completes within a single clearing step.

Remark 7.7 (Transition timing and reassessment receivables).

Disclosure timing and operative legal effect have separate records. Definition 7.4 applies before any local close, transfer, or collection dispatch. The committed position and current complete margin formula determine a proposed close or transfer. Degraded operation retains the preceding requirement under (27).

A governing instrument can authorise retrospective reassessment over a specified window. The rule identifies the canonical obligation, assessment revision, amount due, due time, and collection authority. For an active assessment amount J\ge0, let Y be funded receipts applied to that obligation and V its valid noncash discharges. Let K^{\mathrm{rec}} be collection amounts reserved by unresolved commands. The committed assessment state satisfies Y+V+K^{\mathrm{rec}}\le J,\qquad R^{\mathrm{rec}}:=J-Y-V\ge0,\qquad A^{\mathrm{rec}}:=J-Y-V-K^{\mathrm{rec}}\ge0. Here R^{\mathrm{rec}} is the outstanding receivable and A^{\mathrm{rec}} its unreserved collectible amount. Assessment records a claim, with its existing receipts, discharges, and commands preserved across revisions. A reducing revision must reconcile settled and unresolved amounts, including required refund or adjustment liabilities, before granting new collectible capacity.

A collection command atomically reserves its amount from A^{\mathrm{rec}} and from the payer’s eligible funded pot. That transaction also validates authority, due time, and the current legal-event generation. Concurrent collectors use the same canonical obligation and committed capacity. Valid discharge similarly consumes unreserved obligation capacity, or first reconciles the affected unresolved command. Unresolved reservations persist until actual settlement or terminal evidence of no effect, including a cancellation that prevents later execution. A timeout or generation change alone releases no unresolved capacity.

Command dispatch deduplicates command identity. Receipt processing deduplicates each provider-reported physical transfer occurrence. One command can have multiple distinct partial receipts, which consume its remaining reservation cumulatively. It records actual cash even when the legal generation or assessment revision has changed. It applies the permitted amount to Y, reduces the matching reservation, and credits actual funded cash once. A stale callback initiates no new payment and does not erase an actual receipt. Any amount collected beyond the obligation remains recorded as actual cash with a separate refund liability. The assessment ledger does not invent additional debt to absorb that excess. The provider must supply physical occurrence identifiers and terminal cancellation semantics sufficient for these rules.

The system collects automatically when authority, due time, eligibility, and both available capacities permit. For J=50, Y=V=K^{\mathrm{rec}}=0, and zero payer cash, the creditor records a receivable of 50 and receives zero cash. With payer cash 100, two concurrent collectors can reserve only 50 in aggregate. Unpaid receivables follow the governing default or recovery procedure. A reassessment does not duplicate a trading obligation already included in L_k. Only the resulting outstanding obligation enters an applicable settlement procedure, once and with its priority.

Remark 7.8 (Economic transition frequency and legal events).

Discretionary economic tier changes can incur margin, transfer, and execution costs at each transition. Require spacing \tau_{\mathrm{econ}}>0 between successive discretionary transitions. Their number in an interval of length T is at most 1+\lfloor T/\tau_{\mathrm{econ}}\rfloor. For N transitions, the first-to-last interval is at least (N-1)\tau_{\mathrm{econ}}, which proves the bound. Legal events immediately update action eligibility under Definition 7.4. They bypass the economic timer. Actions that remain eligible can continue under the current economic configuration. Legally required tier changes execute under the applicable rule and are excluded from the discretionary count. A hysteresis band implies a residence-time bound only with suitable rate and jump assumptions on the grade process. The timer and transition-cost model require empirical calibration.

An oracle is the designated source of external prices or event observations used by the calculation. Separate books can still depend on the same oracle, underlying assets, or trading facilities.

Remark 7.9 (Separate default resources for gated pools).

Warm-tier positions in gated pools do not share the insurance fund \mathrm{IF} of the main book. A separate gated-pool fund \mathrm{IF}^{\mathrm{gated}} is sized under the same Cover-k rule (Definition 6.2) against the gated-pool’s stress-scenario set, with separate liquidity tests and shared market and provider stresses, and the waterfall of §6.2 applies within the pool. This separates mutualised default losses. It does not isolate prices, liquidity, or oracles when the gated pool and main book use the same underlying assets or market infrastructure. Liquidation slippage stays within the gated pool’s AMM only when that AMM is also separate. The exogenous-settlement discipline of Theorem 11.2 addresses a different contagion channel.

8 AMM Fire-Sale Contagion Bound

Traditional fire-sale analysis [3, 4] treats the price-impact kernel as an empirically estimated function. The AMM-CCP setting permits a closed-form deterministic bound because the kernel is exact.

8.1 Setup

Consider a first-round liquidation event in which defaulting accounts collectively sell volumes Q_i \geq 0 of spoke asset B_i into pool i for i = 1, \ldots, N. Let P_i(Q_i) denote the realised average price and \Delta P_i(Q_i) := P_i - P_i(Q_i) the slippage. Under Assumption 2.1, for constant-product pools (g_i = 1), \Delta P_i(Q_i) \;=\; P_i \cdot \frac{Q_i}{R_{\!B}^{(i)} + Q_i}. \tag{42} For every fixed g_i>0, with x_i := Q_i/R_{\!B}^{(i)}, the proceeds R_{\!M}^{(i)}[1 - (1 + x_i)^{-g_i}] and the marginal price P_i = g_iR_{\!M}^{(i)}/R_{\!B}^{(i)} give \Delta P_i(Q_i) \;=\; P_i\Bigl(1 - \frac{1 - (1 + x_i)^{-g_i}}{g_i\, x_i}\Bigr) \;=\; P_i\,\frac{g_i + 1}{2}\, x_i\,\bigl(1 + O(x_i)\bigr), which reduces to (42) at g_i = 1 and is increasing in g_i for fixed x_i.

Proposition 8.1 (Finite-sale impact for every positive exponent).

Fix hub reserve R>0, asset reserve B>0, exponent g>0, and sale Q\geq0. Put x=Q/B and P_0=gR/B. With the invariant fixed during the sale, gross proceeds and marked execution loss are \Delta=R[1-(1+x)^{-g}],\qquad S=P_0Q-\Delta=R[gx-1+(1+x)^{-g}]. They satisfy the sharp quadratic bound 0\leq S\leq\frac{g(g+1)}2Rx^2. \tag{43} For Q>0, average-price slippage satisfies 0\leq\frac{S}{P_0Q}\leq\min\left\{1,\frac{g+1}2x\right\}. The terminal marginal-price decline is d_g(x)=1-(1+x)^{-g-1},\qquad 0\leq d_g(x)\leq\min\{1,(g+1)x\}. The quadratic coefficient and both small-sale linear coefficients are optimal. An output fee f\in[0,1) adds f\Delta to the estate’s execution loss.

Proof. Let H(x)=gx-1+(1+x)^{-g}. Then H(0)=H'(0)=0 and 0<H''(x)=g(g+1)(1+x)^{-g-2}\leq g(g+1). The integral identity H(x)=\int_0^x(x-u)H''(u)\,du proves (43). Since \Delta\geq0, also S\leq P_0Q. Dividing by P_0Q gives the average-price bound. The derivative d_g'(x)=(g+1)(1+x)^{-g-2} proves the terminal bound. The limits at x=0 attain each displayed coefficient. For x>0, average slippage equals x^{-1}\int_0^x d_g(u)\,du, so its normalized value increases with g. Subtracting the fee from gross proceeds adds f\Delta to S. ◻

Example 8.2 (Execution under a negative signal).

With g=1/2, R=100, and Q/B=9/16, the proceeds equal 20 and the initial marked sale value P_0Q equals 225/8. The execution loss is 65/8, below the quadratic bound 6075/512. The terminal marginal price is 64/125 of its initial value. This is a funded reserve trade within the negative-signal range of Remark 2.2.

The accounting mark and the average execution price are separate quantities. At cumulative normalized sale x_i=Q_i/R_{\!B}^{(i)}, the terminal marginal-price decline is d_i(x_i)=1-(1+x_i)^{-(g_i+1)}. For constant product, average slippage is x_i/(1+x_i), while terminal decline is 1-(1+x_i)^{-2}. At small size their leading coefficients are one and two. The accounting rule states which terminal or external mark it uses over a fixed horizon h.

The next model follows price declines into account deficiencies and additional sales. Sale volumes are normalized by the initial pool reserves. Holdings determine losses, funded buffers absorb part of them, and a funding policy converts the remaining deficiency into sales. In the expression below, K_h sets accounting marks, A converts their declines into losses, and \mathsf N converts deficiencies into normalized sales.

Definition 8.3 (Cumulative funding response to liquidation marks).

Fix one horizon h, settlement numeraire, reserve vector R_i=R_{\!B}^{(i)}>0, and an initial sale x^0\geq0. Let \bar x\geq x^0 be the cumulative inventory limit, with unique ownership of every unit. The nonnegative matrix A_{kj} records remaining holdings exposure in currency per unit proportional mark decline. The nonnegative matrix B_{ik} records asset-i units sold by the funding policy per currency unit of account-k deficiency. Let b_k\geq0 be the funded deficiency buffer and \mathsf N=\mathop{\mathrm{diag}}(R_i^{-1})B. For each pool’s admitted terminal mark use K_h=I. A nonnegative basket or oracle map K_h requires an explicit accounting-mark rule. The cumulative response target is \Phi(x)=x^0+\min\{\bar x-x^0,\;\mathsf N[A K_h d(x)-b]_+\}. \tag{44} The minimum and positive part are componentwise. With exact linear holdings and funding rules this is the stated response model. With conservative exposure and sale-response envelopes it is a stress upper bound. A dispatch sells only the increase in its cumulative target and consumes its recorded inventory once. Curve proceeds and fees update cash separately under the funded ledger. Covariance estimates price uncertainty and do not specify this causal operator.

A fixed point is a cumulative sale vector that requires no further increase under the stated response policy. The coefficient \gamma_h bounds the response to an additional sale in a weighted maximum norm. Below one, successive responses diminish. The theorem converts that condition into an amplification bound.

Theorem 8.4 (Causal AMM fire-sale response bound).

Under Definition 8.3, define D_g=\mathop{\mathrm{diag}}(g_i+1) and the dimensionless nonnegative matrix T=\mathsf N A K_h D_g. Iteration of \Phi from x^0 increases to its least fixed point in [x^0,\bar x]. For weights w_i>0, let \|x\|_w=\max_i|x_i|/w_i and \gamma_h=\max_i(Tw)_i/w_i. If \gamma_h<1, the fixed point x^* is unique and \begin{aligned} x^*&\leq(I-T)^{-1}x^0,\qquad \|x^*\|_w\leq\frac{\|x^0\|_w}{1-\gamma_h},\\ \mathcal L_{\mathrm{2nd}} &\leq\mathbf1^\top A K_h D_g\bigl[(I-T)^{-1}-I\bigr]x^0. \end{aligned} \tag{45} Here \mathcal L_{\mathrm{2nd}} is the remaining-holdings mark-loss envelope caused by sales after x^0. The first result remains an inventory-bounded least response when the contraction condition fails.

Proof. The map is continuous, monotone, and maps the compact box [x^0,\bar x] into itself. Iteration from x^0 is increasing and bounded. Its coordinatewise limit is a fixed point by continuity and is below every other fixed point by induction. Since 0\leq d_i'(x_i)\leq g_i+1, positive parts and clipping give |\Phi(x)-\Phi(y)|\leq T|x-y|. Thus \gamma_h<1 makes \Phi a contraction in the weighted maximum norm. Also x^*\leq x^0+Tx^*. The nonnegative Neumann series for (I-T)^{-1} gives the first bound. Apply d(x^*)-d(x^0)\leq D_g(x^*-x^0) to the remaining-holdings exposure for the second. For stress envelopes, induction dominates every cumulative realized response whose marks and policy satisfy the recorded envelope. ◻

Corollary 8.5 (Bound for a homogeneous hub-spoke response).

Suppose the constructed funding-response matrix is T=a\{(1-\chi)I+\chi\mathbf1\mathbf1^\top\} with a\geq0 and \chi\in[0,1]. If a\{1+(N-1)\chi\}<1, then \|x^*\|_\infty\leq \frac{\|x^0\|_\infty}{1-a\{1+(N-1)\chi\}}. \tag{46} The coefficients describe holdings, funded buffers, liquidation rules, and reserve depth. They are not return-correlation coefficients.

Proof. Each row sum of T is a\{1+(N-1)\chi\}. Apply Theorem 8.4 with w=\mathbf1. ◻

Remark 8.6 (Computation and unit consistency).

Iteration from \bar x decreases and bounds the least fixed point from above. A finite solver reports lower and upper cumulative targets, or a contraction residual bound. With \gamma_h<1, an iterate x has error at most \|\Phi(x)-x\|_w/(1-\gamma_h). Changing asset units rescales reserves and the matching rows of B together, leaving \mathsf N unchanged. Changing the currency unit rescales A,b and inversely rescales B, leaving the economic target unchanged. An observed venue or funding-policy change requires new coefficients before the response certificate is reused.

Remark 8.7 (Sold and remaining holdings).

For initial holdings H_i and sales Q_i\leq H_i, total loss at accounting mark P_i^{\mathrm{mark}} is Q_iP_i^0-\mathrm{net\ proceeds}_i +(H_i-Q_i)(P_i^0-P_i^{\mathrm{mark}}). The first term uses realized execution proceeds. The second marks only remaining inventory. Charging sale slippage and terminal mark loss on all H_i would count the sold inventory twice. A conservative matrix A is an exposure envelope and does not create another cash debit.

8.2 Incidence of liquidation slippage

The recovery shortfall and output fee fall on the defaulter’s estate. LPs bear divergence loss relative to holding the original reserves at the final price, and retain the fees. These comparisons use different portfolios. The following identity gives both quantities on the same reserve path.

Theorem 8.8 (Incidence of liquidation slippage).

Fix exponents g_i>0 and suppose the liquidation is the only flow in each pool over the event window. Let Q_i\geq0 be the cumulative sale of B_i, f_i\in[0,1) its output fee, and \alpha_{j,i}\geq0 LP j’s pool share. Put x_i=Q_i/R_{\!B}^{(i)}. Fees remain separate from executable reserves during the event and are credited to LPs afterward. All final marks below use the gross curve’s terminal price P_i'=P_i(1+x_i)^{-g_i-1}.

(i)

Recovery shortfall, borne by the estate. Gross curve proceeds are \Delta_M(Q_i;i), net proceeds are \Delta_M^{\mathrm{net}}(Q_i;i):=(1-f_i)\Delta_M(Q_i;i), and \begin{aligned} \Delta_M(Q_i;i)&=R_{\!M}^{(i)}[1-(1+x_i)^{-g_i}],\\ P_iQ_i-\Delta_M^{\mathrm{net}}(Q_i;i) &=R_{\!M}^{(i)}[g_ix_i-1+(1+x_i)^{-g_i}]+f_i\Delta_M(Q_i;i). \end{aligned} \tag{47} The first term is the price-impact shortfall Q_i\Delta P_i(Q_i) and the second is the fee. Both reduce Stage 1 recovery once. At pre-trade marks, the pool’s holdings gain the price-impact amount before fees.

(ii)

Divergence loss, borne by LPs. At the post-trade mark P_i', LP j’s signed loss relative to holding the pre-trade reserves is \mathcal{L}^{\mathrm{LP}}_j=\sum_i\alpha_{j,i}\left[D_i(x_i)-f_i\Delta_M(Q_i;i)\right],\qquad D_i(x)=R_{\!M}^{(i)}\left[1-\frac{1+(g_i+1)x}{(1+x)^{g_i+1}}\right]. \tag{48} The divergence satisfies 0\leq D_i(x)\leq g_i(g_i+1)R_{\!M}^{(i)}x^2/2. Its quadratic leading term equals that of the estate’s price-impact shortfall. For a single pool, writing S=P_0Q-\Delta gives the exact relation S+D=Q(P_0-P_1). A negative signed LP loss means that fees exceed divergence. At g_i=1, the formulas reduce to S_i=\frac{P_iQ_i^2}{R_{\!B}^{(i)}+Q_i},\qquad D_i=\frac{R_{\!M}^{(i)}Q_i^2}{(R_{\!B}^{(i)}+Q_i)^2}. With zero fees, a price-restoring reverse trade retraces the reserve path and restores the original reserves. Actual retained fees change the next executable reserve state and must enter each subsequent leg’s calculation.

Both quantities depend only on cumulative volumes under the fixed-exponent, separate-fee event convention stated above.

Proof. Suppress the pool index and write R=R_{\!M}, B=R_{\!B}, x=Q/B. The invariant gives final reserves R'=R(1+x)^{-g} and B'=B(1+x). Thus P_1=gR(1+x)^{-g-1}/B, and the pool’s gross final value is (1+g)R'. Holding the original reserves instead gives value R+BP_1 at the same mark. Subtracting yields the stated D. Its derivative is D'(x)=Rg(g+1)x(1+x)^{-g-2}. Since D(0)=0, integration proves positivity, the quadratic bound, and its sharp leading coefficient. Direct addition of S and D gives Q(P_0-P_1). Fees add f\Delta to the estate’s cost and the same amount to LP holdings. Pool-share accounting multiplies both LP components by \alpha_{j,i}. Fixed-exponent proceeds telescope over split fills while fees remain outside executable reserves. At g=1, elementary simplification gives the constant-product formulas. The zero-fee inverse trade retraces the same reserve path. ◻

Remark 8.9 (Parameter and fee updates).

The positive-exponent formulas apply at each fixed-parameter execution window, including 0<g_i<1. Immediate fee retention changes executable reserves between fills. A parameter update changes the price attached to a given reserve pair. Both mechanisms require the actual reserve sequence when fills cross their update boundary. The separate-fee event identity supplies a closed-form calculation when its stated event convention applies.

Remark 8.10 (LVR baseline and event-driven loss).

Under Milionis, Moallemi, Roughgarden, and Zhang [54], the continuous-time loss relative to rebalancing accrues at (\sigma_i^2/8)V^{\mathrm{LP}}_{k,i}(t) per pool per unit time for constant product; Proposition 3.23 gives the g_i-weighted rate. Liquidation events add the divergence loss of Theorem 8.8(ii). Optimal-fee calibration [53] can compensate LPs for the baseline. The event-driven component enters the margin and waterfall accounting of §3 and §6 only when pool shares are collateral.

Remark 8.11 (Position of the slippage in the waterfall).

The recovery shortfall (47) enters before the waterfall. It reduces the settlement-asset value recovered at Stage 1. The resulting residual increase is the positive-part difference in (39), with the same obligations and prior commitments. It equals the shortfall when the reference loss already exhausts available collateral. Surplus collateral absorbs the remaining cases. When LP pool shares are not accepted as collateral, LPs stand outside the waterfall. Their signed relative result is (48): divergence loss while the price move persists, net of fees. When LP shares are accepted as collateral, the divergence loss also enters the collateral values in Stages 1, 4, and 5, and LVR becomes a margin input (§3.6).

9 Reflexive Cascade Dynamics

From this section forward we invoke Assumption 2.4. The hub asset’s price P_M has an endogenous component f(L) depending on locked liquidity. This creates a feedback channel not present in the adapted CCP material of §§3-8.

The preceding sale-response model followed cumulative liquidation within a fixed horizon. Here withdrawals change locked liquidity itself, which changes the hub asset’s endogenous value. Ordinary differential equations (ODEs) describe the resulting rates of change through time. They constitute a separate response model with the valuation assumptions stated above.

9.1 Coupled price-liquidity ODE

Definition 9.1 (LP withdrawal dynamics).

The aggregate LP withdrawal rate responds to price declines with a strictly positive, dimensionless elasticity \lambda: a proportional price decline of x per unit time withdraws a fraction \lambda x of locked liquidity per unit time. \dot L(t) \;=\; -\lambda\, L(t) \cdot \bigl[-\dot P_M(t)/P_M(t)\bigr]^{+}, \tag{49} where [x]^+ := \max(0, x).

Definition 9.2 (Liquidation leverage of the clearing layer).

Under Assumption 2.4 the hub price satisfies P_M = V_{\mathrm{ext}} + f(L), and the price equation is \dot P_M \;=\; \theta\bigl(\bar V - P_M + f(L)\bigr) \;+\; \Gamma\, f'(L)\, \dot L, \qquad \Gamma \;\geq\; 1, \tag{50} where \Gamma is the liquidation-leverage factor of the clearing layer: withdrawing one unit of liquidity destroys f'(L) units of endogenous hub value directly, and a further (\Gamma - 1) f'(L) units through liquidity that the clearing layer’s own response removes, namely pool-share collateral that the withdrawal puts into deficit and the clearinghouse redeems, and liquidity that members withdraw to meet the resulting calls. The clearing layer is unlevered when \Gamma = 1, in which case (50) is the exact time derivative of P_M = V_{\mathrm{ext}} + f(L) and no clearing-layer quantity enters the price equation. For \Gamma > 1, (50) is the primitive dynamics and V_{\mathrm{ext}} := P_M - f(L) is derived: \dot V_{\mathrm{ext}} = \theta(\bar V - V_{\mathrm{ext}}) + (\Gamma - 1) f'(L)\dot L, which lies below the mean-reverting drift during withdrawals and is not sign-preserving.

A proportional price decline induces withdrawals, and those withdrawals feed back into price. The following dimensionless coefficient multiplies the two sensitivities and the clearing layer’s amplification. It measures the strength of this specified feedback at the current state.

Definition 9.3 (Reflexivity coefficient).

The reflexivity coefficient is the loop gain of the price-liquidity feedback, \varrho(P_M, L) \;:=\; \Gamma \cdot \frac{\lambda\, L\, f'(L)}{P_M} \;=\; \varrho_{\mathrm{LP}} + \varrho_{\mathrm{clearing}}, \tag{51} where \varrho_{\mathrm{LP}} := \lambda L f'(L)/P_M is the LP component and \varrho_{\mathrm{clearing}} := (\Gamma - 1)\,\varrho_{\mathrm{LP}} is the clearing-layer component. It is dimensionless: \lambda and \Gamma are dimensionless and L f'(L) carries the units of P_M.

In the declining-price regime, substituting Definition 9.1 into (50) and collecting \dot P_M yields the coupled ODE \dot P_M \;=\; \frac{\theta(\bar V - P_M + f(L))}{1 - \varrho}, \qquad \dot L \;=\; \frac{\lambda L}{P_M}\, \dot P_M. \tag{52}

The withdrawal rate reads the same price derivative that it helps determine. We must check whether a proposed derivative satisfies both equations before following it through time. The next proposition lists the consistent choices, including states with more than one choice or none.

Proposition 9.4 (Branch structure of the withdrawal law).

Write g := \bar V - P_M + f(L). At a state with P_M > 0 and L > 0, the pair (49)-(50) admits exactly the following right-derivatives:

(a)

the quiescent branch \dot L = 0, \dot P_M = \theta g, self-consistent iff g \geq 0;

(b)

when \varrho\neq1, the declining branch (52), self-consistent iff g and 1 - \varrho have strictly opposite signs.

Hence exactly one branch is available on \{g > 0,\ \varrho< 1\} (quiescent) and on \{g < 0,\ \varrho< 1\} (declining); both are available on the cascade region \{g > 0,\ \varrho> 1\}; and neither is available on \{g < 0,\ \varrho> 1\}. On the singular surface \{\varrho=1\}, g>0 admits only the quiescent branch, g<0 admits no right-derivative, and g=0 admits the continuum (\dot P_M,\dot L)=\bigl(v,\lambda L v/P_M\bigr),\qquad v\leq0.

Proof. On the quiescent branch [-\dot P_M/P_M]^+ = 0, so \dot L = 0 and (50) gives \dot P_M = \theta g, which is consistent iff g \geq 0. On a declining branch \dot L = \lambda L \dot P_M/P_M, and (50) gives (1 - \varrho)\dot P_M = \theta g. When \varrho\neq1, this is consistent with \dot P_M<0 exactly when g/(1-\varrho)<0. When \varrho=1, the equation requires g=0; if so every v<0 gives the displayed declining derivative, while v=0 is the quiescent derivative. The remaining singular cases follow from the quiescent condition. ◻

Remark 9.5 (Selection, well-posedness, and the trigger).

Equation (49) is an instantaneous law: the withdrawal rate at time t reads the price derivative at time t. By Proposition 9.4 the resulting system is therefore not everywhere determinate, and (52) is a selection on the cascade region rather than the unique resolution there. The lagged law \dot L(t) \;=\; -\lambda\, L(t)\,\bigl[-\dot P_M(t - \Delta_W)/P_M(t - \Delta_W)\bigr]^{+}, \qquad \Delta_W > 0, is determinate: \dot L(t) is fixed by the history and (50) then determines \dot P_M(t) at every state. It does not single out the declining branch on the cascade region. Write r(t) := [-\dot P_M(t)/P_M(t)]^+ and freeze (g, \varrho, P_M) over one lag; substituting the lagged law into (50) gives r(t) = [\varrho\, r(t - \Delta_W) - \theta g/P_M]^+, whose positive fixed point r^* = \theta g/(P_M(\varrho- 1)) is the declining branch (52), with r(t) - r^* = \varrho\,(r(t - \Delta_W) - r^*) while the bracket is positive. On \{g > 0,\ \varrho> 1\} the slope exceeds one and the branch repels: a decline below r^* returns to the quiescent branch in finitely many lags, and one above r^* steepens without bound and leaves the orbit of Theorem 9.7(i). On \{g < 0,\ \varrho< 1\} the slope is \varrho< 1 and the branch attracts, which is Theorem 9.6(a). The selection used below, that on \{g > 0,\ \varrho> 1\} the declining branch is realised when a decline is already underway and the quiescent branch otherwise, is therefore a hypothesis of Theorem 9.7, not a consequence of the lag regularisation: that theorem describes the invariant branch of (52), and a regularisation that realises the branch is Open Problem 5. Two consequences are worth stating. Supercriticality is necessary but not sufficient for collapse: the cascade of Theorem 9.7 requires a trigger, and Proposition 9.11 supplies one. And on \{g < 0,\ \varrho> 1\} the instantaneous law has no forward solution at all, so the model is defined there only through \Delta_W > 0; Theorem 9.7(ii) shows that the trajectories studied below never enter that region, and Corollary 11.6 shows that exogenous settlement makes it unreachable from an admissible state.

9.2 Branchwise local rates near equilibrium

An equilibrium is a state with zero rate of change. Near the equilibrium curve, the rate of return or departure depends on which consistent branch is followed. The theorem states these one-sided rates separately.

Theorem 9.6 (One-sided branchwise rates near equilibrium).

Consider (49)-(50) with f(L) = \beta_L L^\gamma, \gamma \in (0, 1], near a point (P_M^*,L^*) of the equilibrium curve \mathcal{E}= \{P_M = \bar V + f(L)\} with L^*>0 and coefficient \varrho^*. Write \kappa_\theta(\varrho) := \theta\,(1 - \varrho/\Gamma)/(1 - \varrho). The following rates are one-sided and conditional on the named branch; they are not a universal rate for the set-valued instantaneous law.

(a)

Subcritical branches (\varrho^* < 1): below \mathcal{E}, where g>0, the quiescent branch is the only branch and returns at rate \theta. Above \mathcal{E}, where g<0, the declining branch is the only branch and returns at rate \kappa_\theta(\varrho^*)\geq\theta, with equality iff \Gamma=1. In the unlevered case, the local relation \delta P_M=\delta V_{\mathrm{ext}}/(1-\varrho^*) amplifies a perturbation along the declining orbit. It makes no claim about the quiescent branch.

(b)

Approach to the impasse from the subcritical declining branch (\varrho^*\to1^-): if \Gamma>1, then \kappa_\theta\to\infty. If \Gamma=1, then \kappa_\theta=\theta for every \varrho^*<1. The cancellation is branchwise. The constrained system remains singular on \Sigma.

(c)

Selected supercritical declining branch (1 < \varrho^* < \Gamma): on \{g > 0,\ \varrho> 1\} this branch has \dot P_M = \theta g/(1 - \varrho) < 0. Perturbations below \mathcal{E} grow at rate -\kappa_\theta(\varrho^*) = \theta\,(1 - \varrho^*/\Gamma)/(\varrho^* - 1)>0, which diverges as \Sigma is approached from above. The quiescent branch also exists in this region.

(d)
Equilibrium subcriticality condition. At (P_M^*, L^*) \in \mathcal{E}, \Gamma\lambda\gamma < \frac{P_M^*}{V_{\mathrm{end}}^*} = 1 + \frac{\bar V}{V_{\mathrm{end}}^*}, \qquad V_{\mathrm{end}}^* = f(L^*). \tag{53}

Proof. On the quiescent branch \dot L = 0 and \dot P_M = \theta g with g = \bar V + f(L) - P_M, so \dot P_M = -\theta(P_M - P_M^*) exactly at fixed L. On the declining branch L moves with P_M: dividing the two components of (52) gives dL/dP_M = \lambda L/P_M, so along that orbit g'(P_M) = f'(L)\lambda L/P_M - 1 = \varrho/\Gamma - 1 and \dot P_M = \theta g/(1 - \varrho) \approx -\kappa_\theta(\varrho^*)(P_M - P_M^*). The same branchwise rate follows from the desingularised Jacobian (57): its non-zero eigenvalue is -\theta(1 - \varrho^*/\Gamma) in rescaled time s, and dt = (1 - \varrho)\,ds converts it to -\kappa_\theta(\varrho^*) in t. For (a), \kappa_\theta \geq \theta iff \Gamma \geq 1. When \Gamma=1, \dot V_{\mathrm{ext}} = \theta(\bar V - V_{\mathrm{ext}}) and differentiation along the declining orbit gives dV_{\mathrm{ext}}/dP_M=1-\varrho, hence the stated amplitude relation. For (c), \varrho^* < \Gamma makes 1 - \varrho^*/\Gamma > 0. For (d), \varrho^* = \Gamma\lambda\gamma V_{\mathrm{end}}^*/P_M^* because L f'(L) = \gamma f(L), and \varrho^* < 1 is (53). ◻

9.3 Finite-time collapse on the supercritical branch

The next theorem starts after the declining branch has been selected. Its proof first identifies the curve linking price and liquidity, then shows that the trajectory stays in the declining region. A finite integral bounds the elapsed time to its endpoint. The branch-selection premise remains separate from those conclusions.

Theorem 9.7 (Finite-time collapse on the invariant cascade branch).

Consider (52) with f(L) = \beta_L L^\gamma, \gamma \in (0, 1], and suppose \lambda\gamma < 1. Let the initial state lie on the cascade branch: P_{M,0} < \bar V + f(L_0) and \varrho(P_{M,0}, L_0) > 1, with the declining branch of Proposition 9.4(b) selected at t = 0, the selection hypothesis of Remark 9.5. These hypotheses require a sufficiently levered clearing layer. Indeed, \varrho_0 = \Gamma\lambda\gamma f(L_0)/P_{M,0} and f(L_0) \leq P_{M,0} by the initial condition of Assumption 2.4, so \varrho(P_{M,0}, L_0) > 1 forces \Gamma \;>\; \frac{P_{M,0}}{\lambda\gamma\, f(L_0)} \;\geq\; \frac{1}{\lambda\gamma} \;>\; 1 . Then:

(i)

Orbit integral. L(t) = L_0\, (P_M(t)/P_{M,0})^\lambda; the trajectory is confined to this curve.

(ii)

Branch invariance. Along the orbit, \varrho is strictly increasing as P_M falls, and the equilibrium gap g(P_M) := \bar V + f(L(P_M)) - P_M satisfies g \geq g_{\min} := \min\{\bar V,\; \bar V + f(L_0) - P_{M,0}\} > 0. The trajectory neither re-crosses \Sigma = \{\varrho= 1\} nor reaches the equilibrium set \mathcal{E}.

(iii)

Finite-time collapse. P_M(t) and L(t) decrease monotonically to 0, reached at a finite time T^* \;\leq\; \frac{\Gamma\, f(L_0) - P_{M,0}}{\theta\, g_{\min}}. On the way, the derived exogenous component V_{\mathrm{ext}} = P_M - f(L) reaches zero at the price P_1 := A^{1/(1 - \lambda\gamma)} \leq P_{M,0}, where A := \beta_L L_0^\gamma P_{M,0}^{-\lambda\gamma}, at a time T_1 \leq T^*. Below P_1 the price is less than the endogenous component f(L): the levered layer’s forced liquidations have driven the market price below the value the remaining liquidity supports, and the collapse to zero is a statement about the primitive dynamics (50), beyond the decomposition of Assumption 2.4.

The cascade does not stop at the exogenous anchor \bar V: on the invariant branch the reflexive channel outruns mean reversion at every price level, and mean reversion enters only through g_{\min}, which sets the collapse speed, not the destination. Termination requires removing the invariant branch itself. Under the settlement discipline of Definition 11.1, exogenous-settlement severance forces \Gamma = 1 and caps \varrho at \lambda\gamma. With the same hypothesis \lambda\gamma < 1 assumed here, every dynamically admissible state is subcritical (Theorem 11.2 and Corollary 11.6).

Proof. (i) From (52), dL/dP_M = \lambda L/P_M — the singular prefactor 1/(1-\varrho) cancels in the ratio. Separation of variables gives the orbit.

(ii) Along the orbit, f(L(P_M)) = A\,P_M^{\lambda\gamma} with A := \beta_L L_0^\gamma P_{M,0}^{-\lambda\gamma}, and since L f'(L) = \gamma f(L), \varrho(P_M) \;=\; \frac{\Gamma\lambda\gamma\, f(L(P_M))}{P_M} \;=\; \Gamma\lambda\gamma A\, P_M^{\lambda\gamma - 1}, which is strictly decreasing in P_M exactly when \lambda\gamma < 1; so \varrho rises as the price falls and stays above \varrho_0 > 1. For the gap: g(P_M) = \bar V + A P_M^{\lambda\gamma} - P_M is concave in P_M (second derivative A\lambda\gamma(\lambda\gamma - 1)P_M^{\lambda\gamma - 2} < 0), with g(0^+) = \bar V > 0 and g(P_{M,0}) > 0 by the branch hypothesis; concavity bounds g on [0, P_{M,0}] below by the smaller endpoint value, giving g \geq g_{\min}. With g > 0 and \varrho> 1 persistent, \dot P_M = \theta g/(1 - \varrho) < 0 throughout: the declining branch of Proposition 9.4(b) remains self-consistent and, having been selected at t = 0, remains selected, since the orbit does not leave \{g > 0,\ \varrho> 1\}. The trajectory meets neither \Sigma nor \mathcal{E}, and in particular never enters the region \{g < 0,\ \varrho> 1\} on which no branch closes.

(iii) Time along the orbit is dt = \dfrac{\varrho(P) - 1}{\theta\, g(P)}\,dP integrated downward from P_{M,0}, so \begin{align*} T^* &=\int_0^{P_{M,0}}\frac{\varrho(P)-1}{\theta g(P)}\,dP\\ &\leq\frac1{\theta g_{\min}}\int_0^{P_{M,0}} \bigl(\Gamma\lambda\gamma A P^{\lambda\gamma-1}-1\bigr)\,dP\\ &=\frac{\Gamma A P_{M,0}^{\lambda\gamma}-P_{M,0}}{\theta g_{\min}} =\frac{\Gamma f(L_0)-P_{M,0}}{\theta g_{\min}}<\infty. \end{align*} using \varrho> 1 along the orbit for the sign of the integrand, \lambda\gamma < 1 for the convergence of the integral at 0, and the compatibility inequality, \Gamma f(L_0) > P_{M,0}/(\lambda\gamma) > P_{M,0}, for the positivity of the numerator. Monotone decline plus a finite time budget forces P_M \to 0 at T^*; the orbit gives L = L_0(P_M/P_{M,0})^\lambda \to 0. For the boundary: along the orbit f(L(P))/P = A P^{\lambda\gamma - 1}, which is decreasing in P, equals 1 at P_1 = A^{1/(1 - \lambda\gamma)}, and is at most 1 at P_{M,0} by the initial condition, so P_1 \leq P_{M,0} and V_{\mathrm{ext}} < 0 below P_1. At P_1, \varrho= \Gamma\lambda\gamma, which exceeds 1 by the compatibility inequality, so the crossing lies on the cascade branch and T_1 \leq T^*. ◻

Remark 9.8 (The collapse endpoint).

Prior treatments of reflexive collapse [14, 15] are qualitative. The orbit integral (i) reduces the two-dimensional flow to a scalar equation along an invariant curve, and branch invariance (ii) is what makes the reduction global on the cascade branch: no Lyapunov function or limit-set argument is needed, and none would deliver the endpoint, which is (0, 0) rather than any equilibrium of the flow. The statement is about the invariant branch of (52) under the selection hypothesis of Remark 9.5; which path a regularised withdrawal law realises from the cascade region is Open Problem 5.

Remark 9.9 (The boundary and self-extinguishing regime \lambda\gamma \geq 1).

At \lambda\gamma = 1, \varrho is constant along the orbit. The collapse conclusion persists because the time integrand is bounded. Thus, T^* is finite a fortiori. For \lambda\gamma > 1, \varrho decreases as the price falls: a supercritical cascade weakens as it runs and can re-cross \Sigma. The crossing leaves the scalar reduction through the blow-up of |\dot P_M| at the impasse surface (Proposition 10.4); the finer structure of trajectories at the crossing is posed as Open Problem 5.

9.4 Liquidity concentration and a single provider withdrawal

The withdrawal dynamics of Definition 9.1 treat L(t) as aggregate locked liquidity. When the LP distribution is concentrated, a single LP’s withdrawal moves L discontinuously. Whether such a jump can carry a subcritical state across \Sigma depends on the price response, and the answer separates the levered from the unlevered clearing layer.

Definition 9.10 (LP concentration).

Let \alpha_j \geq 0 denote LP j’s share of aggregate L with \sum_j \alpha_j = 1. The LP Herfindahl index is H := \sum_j \alpha_j^2 \in [0, 1]; the maximum share is s_{\max} := \max_j \alpha_j \in [0, 1]. A pool is LP-diffuse if s_{\max} is bounded above by a threshold \bar s; otherwise it is LP-concentrated.

Proposition 9.11 (Single-LP withdrawal and the critical locus).

Let f(L) = \beta_L L^\gamma with \gamma \in (0, 1). At t_0^-, suppose that f(L(t_0^-))\leq P_M(t_0^-) and define the subcritical coefficient \varrho^- := \varrho(P_M(t_0^-),L(t_0^-))<1. Let a single LP with share s:=s_{\max} withdraw at t_0, so that L(t_0^+)=(1-s)L(t_0^-).

(i)

At a fixed price the withdrawal is protective. If P_M is unchanged, \varrho(t_0^+) = (1 - s)^\gamma \varrho^- < \varrho^-.

(ii)

With an exogenous price jump. If the withdrawal coincides with a drop P_M(t_0^+) = (1 - \delta_P)P_M(t_0^-), \delta_P \in [0, 1), then \varrho(t_0^+) = (1 - s)^\gamma\varrho^-/(1 - \delta_P), and the state crosses \Sigma iff \delta_P \;>\; 1 - (1 - s)^\gamma\, \varrho^- . \tag{54} The price jump causes the crossing; a larger withdrawal raises the required price jump.

(iii)
With the price response of the model. If the price responds to the impulse through (50) alone, P_M(t_0^+) = P_M(t_0^-) - \Gamma\bigl(f(L(t_0^-)) - f(L(t_0^+))\bigr), then \varrho(t_0^+) is increasing in s iff \Gamma f(L(t_0^-)) > P_M(t_0^-). Suppose \lambda\gamma < 1 and \Gamma f(L(t_0^-)) > P_M(t_0^-). Define s^* \;:=\; 1 - \left(\frac{\Gamma f(L(t_0^-)) - P_M(t_0^-)}{(1 - \lambda\gamma)\,\Gamma f(L(t_0^-))}\right)^{1/\gamma}, \qquad s^{\mathrm{exh}} \;:=\; 1-\left(1-\frac{P_M(t_0^-)}{\Gamma f(L(t_0^-))}\right)^{1/\gamma}. \tag{55} Among impulses with P_M(t_0^+)>0, the coefficient crosses \Sigma exactly when s^*<s<s^{\mathrm{exh}}. Write u=(1-s)^\gamma, F=f(L(t_0^-)), and P=P_M(t_0^-). The post-impulse gap is g^+=\bar V+\Gamma F-P-(\Gamma-1)Fu. Entry into the cascade region additionally requires g^+>0. Equivalently, the positive-price cascade region after the impulse is 1-\frac{P}{\Gamma F}<u< \min\left\{ \frac{\Gamma F-P}{(1-\lambda\gamma)\Gamma F}, \frac{\bar V+\Gamma F-P}{(\Gamma-1)F} \right\}. A subsequent collapse trajectory also requires the declining-branch selection in Theorem 9.7. At s=s^{\mathrm{exh}} the impulse reaches P_M(t_0^+)=0. A larger proposed withdrawal reaches the boundary before the full impulse completes, so the positive-price model supplies no post-impulse state. Since f(L) \leq P_M at the initial state, \Gamma f(L) > P_M requires \Gamma > 1: within the model, a single withdrawal can trigger a cascade only through a levered clearing layer, and under the settlement discipline of Definition 11.1 it cannot.

Proof. With L f'(L) = \gamma f(L), \varrho= \Gamma\lambda\gamma f(L)/P_M and f((1-s)L) = (1-s)^\gamma f(L). (i) and (ii) are immediate; rearranging \varrho(t_0^+) > 1 gives (54). (iii) Integrating (50) across the instant of the withdrawal, the \theta-term contributes nothing and \int \Gamma f'(L)\dot L\,dt = \Gamma[f(L(t_0^+)) - f(L(t_0^-))], which gives the stated P_M(t_0^+). Write u := (1 - s)^\gamma \in (0, 1], F := f(L(t_0^-)), and P := P_M(t_0^-). Then P_M(t_0^+)=P-\Gamma F+\Gamma Fu and \varrho(t_0^+) = \Gamma\lambda\gamma F u/(P - \Gamma F + \Gamma F u). On the positive-price domain, its derivative in u has the sign of P - \Gamma F, so \varrho(t_0^+) increases with s iff \Gamma F > P. The price is positive exactly when u>1-P/(\Gamma F), or s<s^{\mathrm{exh}}. The condition \varrho(t_0^+) > 1 is \Gamma F u(\lambda\gamma - 1) > P - \Gamma F; with \lambda\gamma < 1 this is u < (\Gamma F - P)/((1 - \lambda\gamma)\Gamma F), or s>s^*. The upper bound on u lies below 1 exactly when \varrho^- < 1. It exceeds the price-exhaustion lower bound because 1/(1-\lambda\gamma)>1. Thus s^*<s<s^{\mathrm{exh}} is precisely the positive-price crossing range. The gap rises by (\Gamma-1)F(1-u)\geq0, but its initial value can be negative. Substitution gives the displayed g^+ and its independent positivity condition. For F=1, P=2, \Gamma=3, \lambda\gamma=1/2, \bar V=1/10, and u=3/5, the post-price is 4/5 and \varrho^+=9/8, while g^+=-1/10. Thus this state is coefficient-supercritical and outside the cascade region. At the same parameters with u=21/40, the post-price is 23/40, f(L^+)=21/40, \varrho^+=63/46>1, and g^+=1/20>0. The latter impulse also preserves f(L^+)\leq P_M^+, giving an admissible initial state for Theorem 9.7 under its branch selection. ◻

Remark 9.12 (Liquidity concentration and funding liquidity).

Proposition 9.11 is the AMM-CCP form of the Brunnermeier-Pedersen [27] funding-liquidity spiral, with one qualification the model adds: concentrated LP capital is a systemic exposure only when the price responds to its withdrawal by more than the endogenous value withdrawn, \Gamma f(L) > P_M, which a levered clearing layer produces and an unlevered one cannot. In the levered case an LP-concentration cap s_{\max}<s^* keeps every single withdrawal strictly subcritical, and the weak cap s_{\max}\leq s^* keeps it non-supercritical. A per-LP withdrawal-rate limit converts a jump into a path along which Theorem 9.6(a) applies. Trading off LP-scale efficiency, which fee revenue pushes toward concentration, against the cap is Open Problem 9.

10 Classification of the Critical Locus \varrho= 1

At \Sigma := \{\varrho= 1\}, the coefficient multiplying the price derivative vanishes. The next analysis distinguishes a collision of equilibria from a failure of the equations to specify a finite rate. It tests the fold conditions on a rescaled field, then identifies the impasse in the original time variable.

10.1 Desingularization

Equation (52) is the constrained system A(x)\,\dot x = F(x) with x = (P_M, L) and \det A(x) = 1 - \varrho(x), so it is singular exactly on \Sigma. Rescale time: ds := dt/(1 - \varrho) on the subcritical sheet \{\varrho< 1\}. This is the standard desingularization of a constrained system at an impasse surface [24, 25]. Multiplying through gives the smooth two-dimensional field \frac{dP_M}{ds} = \theta(\bar V - P_M + f(L)), \qquad \frac{dL}{ds} = \frac{\lambda L}{P_M}\, \theta(\bar V - P_M + f(L)). \tag{56}

The new time coordinate removes the vanishing denominator and permits analysis of the equilibrium geometry. Physical-time continuation through the singular surface still requires the original equations. The matrix denoted A in the Jacobian calculation below is the derivative of the rescaled field. It differs from the constraint matrix used to classify the original system.

Proposition 10.1 (Equilibria of the desingularized flow).

The equilibria of (56) in \{P_M > 0, L \geq 0\} are exactly \mathcal{E}= \{(P_M, L)\,:\, P_M = \bar V + f(L),\ L \geq 0\}.

Proof. Setting both components to zero requires \theta(\bar V - P_M + f(L)) = 0; the second component then vanishes automatically. ◻

10.2 Sotomayor conditions on the desingularized flow

Sotomayor’s theorem [23, Thm. 3.4.1][22, Thm. 3.4] classifies a parametrised equilibrium as a fold if the Jacobian A = D_x F has a simple zero eigenvalue with right null v and left null w^\top, and the following conditions hold:

(S1)

\dim\ker A=1, and every non-zero eigenvalue has non-zero real part.

(S2)

w^\top D_{xx}^2 F(x^*, \mu_0)[v, v] \neq 0.

(S3)

w^\top D_\mu F(x^*, \mu_0) \neq 0 (transversality).

We instantiate on (56). The Jacobian at an equilibrium (P_M^*, L^*) \in \mathcal{E} is A = \begin{pmatrix} -\theta & \theta f'(L^*) \\ (\lambda L^*/P_M^*)(-\theta) & (\lambda L^*/P_M^*)\,\theta f'(L^*) \end{pmatrix}. \tag{57}

Lemma 10.2 (Rank deficiency on \mathcal{E}).

At every equilibrium (P_M^*, L^*) \in \mathcal{E} with L^* > 0, A has rank one: row 2 = (\lambda L^*/P_M^*)\cdot row 1. Consequently, \det A = 0 and 0 \in \sigma(A) for all such equilibria, independent of any bifurcation parameter.

Proof. Direct from (57): each entry of row 2 equals (\lambda L^*/P_M^*) times the corresponding entry of row 1. ◻

Lemma 10.3 (\Sigma = \{\varrho= 1\} is not a Sotomayor fold).

Parametrise the family (56) by the leverage factor \mu:=\Gamma, holding \lambda, \gamma, and \beta_L fixed, so that \varrho^*=\Gamma\lambda\gamma f(L^*)/P_M^* crosses 1 as \Gamma varies. At any equilibrium (P_M^*,L^*)\in\mathcal{E} with \varrho^*=1, the desingularized field is independent of \mu. Hence Sotomayor’s transversality condition (S3) fails. The zero eigenvalue is tangent to the equilibrium curve that persists for every \mu; it does not describe a collision of two isolated equilibria. The fold bifurcation does not occur.

Proof. The field in (56) contains no \Gamma, so D_\mu F\equiv0 and w^\top D_\mu F=0. Thus (S3) fails. Lemma 10.2 also identifies the persistent null direction: the equilibrium set is a curve for every \mu, and its tangent lies in the kernel. This is not a saddle-node collision. ◻

10.3 Correct classification: \Sigma is an impasse surface

Proposition 10.4 (\Sigma is an impasse surface: the scalar reduction fails and |\dot P_M| \to \infty on approach).

Write (52) in constrained form A(x)\,\dot x = F(x) with x = (P_M, L): (1 - \varrho)\, \dot P_M = \theta(\bar V - P_M + f(L)), \qquad \dot L - \frac{\lambda L}{P_M}\, \dot P_M = 0, so that \det A(x) = 1 - \varrho(x) and \Sigma = \{\det A = 0\}. Then:

(i)

\Sigma is an impasse surface in the sense of Takens [24] and Riaza [25]: at a point of \Sigma with F \neq 0 no \dot x solves A\dot x = F, so the scalar reduction of (52) to P_M has no continuous extension across \Sigma. Along any trajectory approaching \Sigma with \theta(\bar V - P_M + f(L)) bounded away from zero, |\dot P_M| \to \infty and the remaining t-time to \Sigma is finite.

(ii)

The points of \mathcal{E}\cap \Sigma — exactly the equality case of (53) — are equilibrium–impasse intersections: an equilibrium of the flow lies on the surface where the constraint matrix drops rank. They are the configurations at which a singularity-induced bifurcation can occur in the sense of Venkatasubramanian, Schättler, and Zaborszky [26]. Calling a particular parameterised passage a bifurcation also requires the corresponding transversality and non-degeneracy conditions; those conditions are not assumed here.

(iii)
Reading \varepsilon := 1 - \varrho as a singular-perturbation parameter does not place the system in slow-fast form, and Fenichel’s theorem [18] does not apply on \Sigma.

Proof. (i) Here A(x) = \begin{pmatrix} 1 - \varrho& 0 \\ -\lambda L/P_M & 1\end{pmatrix} and F(x) = (\theta(\bar V - P_M + f(L)), 0)^\top, so \det A = 1 - \varrho, which vanishes exactly on \Sigma. On \Sigma the first row of A\dot x = F reads 0 = \theta(\bar V - P_M + f(L)), which fails whenever F \neq 0; off \Sigma the system is the explicit field (52), and |\dot P_M| = |\theta(\bar V - P_M + f(L))|/|1 - \varrho| \to \infty as \varrho\to 1 with the numerator bounded away from zero. For the finite time: along the trajectory dt = (1 - \varrho)\,dP_M/\bigl(\theta(\bar V - P_M + f(L))\bigr), whose integrand is bounded on the remaining bounded P_M-interval, so the integral converges. Both statements are the classical impasse phenomenon [24, 25].

(ii) By Proposition 10.1, \mathcal{E} is the equilibrium set of the desingularized field (56), and \varrho^* = 1 on \mathcal{E} is the equality case of (53). Thus \mathcal{E}\cap\Sigma is exactly the set of equilibria on \{\det A=0\}. This is the equilibrium–singularity configuration used in singularity-induced bifurcation theory [26]; the statement makes no unproved transversality claim.

(iii) Dividing the two components of (52) gives \dot L/\dot P_M = \lambda L/P_M, an O(1) ratio, so \dot L is O(1/\varepsilon) wherever \dot P_M is: the two components share one timescale and neither variable is slow. Independently, Fenichel’s theorem requires \varepsilon to be a small positive constant in a neighbourhood of the slow manifold, whereas here \varepsilon is state-dependent and vanishes on \Sigma. ◻

Remark 10.5 (Consequences of the impasse classification).

Keeping \varrho^* \ll 1 preserves an O(1) margin \det A = 1 - \varrho to the impasse surface. A fold would imply a structurally stable two-equilibrium picture near the threshold; the impasse classification instead implies that a trajectory reaching \Sigma leaves the scalar reduction through a blow-up of |\dot P_M| in finite time, beyond which the reduced model is silent, consistent with the rapid collapse observed in Terra/Luna (May 2022) and Iron Finance (June 2021) [14, 15, 17]. The finer structure of the crossing is posed as Open Problem 5.

11 Exogenous-Settlement Severance

The reflexive cascade of Section 9 needs a levered clearing layer: the supercritical branch requires \Gamma > 1, and \Gamma > 1 means that clearing actions themselves withdraw locked liquidity. This section states the discipline that makes \Gamma = 1, and what it does and does not remove. The discipline reflects PFMI Principles 5 and 16 and EMIR Articles 46–47 on collateral and custody [48, 49]. The theorem says what that discipline severs in the coupled model, and which channels own-token and LP-share collateral leave open.

11.1 The severance theorem

Definition 11.1 (Exogenous settlement asset; settlement discipline).

A settlement asset is central-bank money, commercial-bank money, or an eligible stablecoin used to discharge obligations. Eligibility is a legal and operational decision. It is separate from the model’s exogeneity condition. This model takes an eligible asset S whose price process P_S(t) is independent of the locked-liquidity process L(t). The clearing layer is denominated in S if

(a)

margin requirements, position marks, and the insurance fund’s default capacity are expressed in S-units;

(b)

eligible collateral is held in S: LP pool shares and the hub asset M are ineligible;

(c)

margin calls are discharged by final transfers of S on the funding clock, and no action of the waterfall (seizure, liquidation, fund draw, socialisation, auto-deleveraging) redeems pool shares or otherwise withdraws locked liquidity. The external provider’s rulebook determines finality for each transfer.

Condition (c) is behavioural as well as structural: a member who redeems pool shares to meet a call in S withdraws liquidity through the clearing layer, a channel outside the withdrawal law of Definition 9.1.

Theorem 11.2 (Exogenous-settlement severance).

Under Assumption 2.4, if the clearing layer is denominated in S in the sense of Definition 11.1, then no clearing action changes L, so the liquidation-leverage factor of Definition 9.2 is \Gamma = 1: the clearing-layer component of the reflexivity coefficient vanishes, \varrho_{\mathrm{clearing}} = (\Gamma - 1)\varrho_{\mathrm{LP}} = 0, and \varrho= \varrho_{\mathrm{LP}} = \lambda L f'(L)/P_M at every state. The loop P_M \downarrow \Rightarrow \text{margin calls} \Rightarrow \text{liquidations} \Rightarrow L \downarrow \Rightarrow f(L) \downarrow \Rightarrow P_M \downarrow is broken at its third arrow. What severance does not remove is the position-loss channel: positions exposed to M still lose S-value when P_M falls, still enter deficit, and are still liquidated. Those losses are absorbed by the waterfall of §6.2 and, within the model, have no effect on P_M, because the endogenous component of P_M depends on L alone and the liquidations do not touch L.

Proof. By Definition 9.2, (\Gamma - 1) f'(L) is the endogenous hub value destroyed per unit of withdrawn liquidity through liquidity that the clearing layer’s own actions remove. Under (b), seized collateral contains no pool shares, so liquidating it redeems none; under (c), margin calls are met in S and no waterfall action withdraws liquidity. Hence the only process that changes L is the LP withdrawal law (49), the endogenous value destroyed per unit of withdrawal is f'(L) and nothing more, and (50) is the exact time derivative of P_M = V_{\mathrm{ext}} + f(L), which is \Gamma = 1. A liquidation that withdraws no liquidity leaves f(L), hence P_M, unchanged. This is the position-loss statement. ◻

Remark 11.3 (Own-token and LP-share collateral).

The two ways of violating Definition 11.1 open different loops. LP-share collateral (a violation of (b)) makes seizure and liquidation redeem pool shares, which is \Gamma > 1 directly and is the loop the model represents (§3.6). Own-token collateral marks collateral in M, so a fall in P_M shrinks every collateral balance at once and forces liquidations of M itself; that loop runs through the market for M, which the model, with V_{\mathrm{ext}} exogenous, does not represent. The model’s severance result speaks to the first; the second is excluded by (b) and lies outside the model’s price equation.

Settlement denomination alone does not establish the behavioral condition in Definition 11.1(c). The next calculation records remaining funding paths when members meet cash calls through redemptions or external sales. Its calibrated response coefficients and horizon specify the additional model being tested.

Proposition 11.4 (Residual funding-channel sensitivity).

Fix a calibrated response region and horizon h. Let p\geq0 be cumulative proportional price decline, z\geq0 its exogenous initiating shock, and k=Lf'(L)/P_M at the reference state. Normalize funding by a recorded funded base and liquidity by its reference amount. Suppose the cumulative funding gap is g(p)=[\beta p-b]_+. Its liquidity withdrawal is \alpha g(p) and direct external-venue mark pressure is \nu g(p). All coefficients are nonnegative and dimensionless. The response envelope is p=z+k\lambda p+(k\alpha+\nu)[\beta p-b]_+. If G:=k\lambda+(k\alpha+\nu)\beta<1, it has a unique nonnegative fixed point with p\leq z/(1-G), provided that bound remains in the calibrated region. The case \alpha=\nu=0 gives the unlevered within-model coefficient k\lambda.

Proof. The scalar map is nonnegative, increasing, and G-Lipschitz. Banach contraction gives a unique fixed point. Since [\beta p-b]_+\leq\beta p, the fixed point satisfies p\leq z+Gp. Rearrange to obtain the bound. The same induction gives an upper envelope for a realized response bounded by these channel coefficients. ◻

Remark 11.5 (Nonzero funding paths under exogenous denomination).

Credit-line or margin withdrawals contribute to \beta. LP redemptions and shared ownership contribute to \alpha. Asset sales and cross-venue price pressure contribute to \nu. For k=0.4, \lambda=1, \alpha=0.5, \nu=0.1, \beta=0.5, b=0, and z=0.02, G=0.55 and p=2/45. At \beta=2, G=1 and this finite contraction bound ceases to apply despite unchanged settlement denomination. That boundary does not itself prove a collapse trajectory. The original severance theorem concerns its specified clearing-induced withdrawal channel. The additional response certificate covers recorded external funding paths.

Corollary 11.6 (Cascade exclusion under exogenous settlement).

Take f(L) = \beta_L L^\gamma with \gamma \in (0, 1], the initial condition V_{\mathrm{ext}}(0) \geq 0 of Assumption 2.4, and the settlement discipline of Definition 11.1. Then \varrho(P_M, L) \;=\; \frac{\lambda\gamma\, f(L)}{P_M} \;\leq\; \lambda\gamma \qquad \text{along every trajectory.} \tag{58} Consequently, if the LP withdrawal elasticity satisfies \lambda\gamma < 1, the dynamically admissible region \{P_M\geq f(L)\} contains no supercritical state. No trajectory satisfying the stated initial condition reaches the critical locus \Sigma; the cascade branch of Theorem 9.7 is unavailable along every such trajectory; and Proposition 9.4 gives a unique right-derivative there. The condition \lambda\gamma < 1 under which a selected cascade runs to zero in finite time is therefore also sufficient to prevent an unlevered clearing layer from starting one from an admissible state.

Proof. By Theorem 11.2, \Gamma = 1, so \varrho= \lambda L f'(L)/P_M = \lambda\gamma f(L)/P_M using L f'(L) = \gamma f(L), and \dot V_{\mathrm{ext}} = \theta(\bar V - V_{\mathrm{ext}}) exactly; with V_{\mathrm{ext}}(0) \geq 0 this gives V_{\mathrm{ext}}(t) \geq \min(V_{\mathrm{ext}}(0), \bar V) \geq 0, so f(L)/P_M \leq 1 along the trajectory, which is (58). If \lambda\gamma < 1 then \varrho\leq \lambda\gamma < 1 at every point of each admissible trajectory. Theorem 9.7 requires \varrho(P_{M,0}, L_0) > 1, so no admissible initial state satisfies its hypotheses under exogenous settlement. Proposition 9.4 gives a unique right-derivative wherever \varrho< 1. ◻

Corollary 11.7 (Settlement denomination and drawable resources).

Fix D, \mathcal{B}, and \mathcal{P} at clearing time. Define funded resources and eligible profit claims by \begin{aligned} \mathcal{C}^{\mathrm{pref}}(D)&:=\sum_{k\in D}C_k+E_{\mathrm{SIG}}+\mathrm{IF}+\sum_{k\in\mathcal{B}}a_k,\\ \mathcal{C}^{\mathrm{ADL}}(D)&:=\sum_{k\in\mathcal{P}}\pi_k,\\ \mathcal{C}^{\mathrm{abs}}(D)&:=\mathcal{C}^{\mathrm{pref}}(D)+\mathcal{C}^{\mathrm{ADL}}(D). \end{aligned} \tag{59} The waterfall absorbs defaulters’ gross loss exactly when it does not exceed \mathcal{C}^{\mathrm{abs}}(D). Set \widehat{\mathcal{C}}^{\mathrm{pref}}(D):= \sum_{k\in D}C_k+E_{\mathrm{SIG}}+\mathrm{IF} +\kappa\sum_{k\in\mathcal{B}}C_k. Then \mathcal{C}^{\mathrm{pref}}(D)=\widehat{\mathcal{C}}^{\mathrm{pref}}(D) -\sum_{k\in\mathcal{B}}[s_k+b_k-(1-\kappa)C_k]_+. Under Definition 11.1, fixed settlement-asset quantities have no direct hub-price revaluation. The deduction records collateral consumed or reserved after settlement. Position losses can therefore reduce drawable resources even when collateral remains denominated in the settlement asset. Profit claims also vary with position marks.

Proof. The exact residual follows from Theorem 6.12. The decomposition follows from \min\{\kappa C,C-s-b\}=\kappa C-[s+b-(1-\kappa)C]_+. External denomination fixes the unit of account. The deduction separately records consumption and encumbrance. ◻

Corollary 11.8 (Correlated-depeg residual).

Freeze allocated collateral reference value W_C\ge0 and unhaircut reserve reference value W_R\ge0. These quantities identify disjoint assets allocated to the stated credit and reserve exposures. Senior obligations and their reserved backing have their own entries in the funded ledger. The following bound concerns these fixed valuation exposures, rather than the full deficit after arbitrary changes in legal priority. With haircut h_S\in[0,1], their credited amount is (1-h_S)W_C+W_R. For depeg \delta_S\in[0,1], define collateral shortfall and reserve loss by X_C:=(\delta_S-h_S)_+W_C,\qquad X_R:=\delta_SW_R. Let A_q and B_q be the settlement-asset and hub-asset lower q-tail events. Assume \delta_S\le h_S outside A_q and \delta_S\le\delta_q inside it, where h_S\le\delta_q\le1. Suppose the lower tail-dependence coefficient \lambda^L_{SM} exists, so p_q:=\mathbb{P}(A_q\mid B_q)=\lambda^L_{SM}+o_q(1) [10, 11]. Then \Delta^{(2)}_{SM}:=\mathbb{E}[X_C+X_R\mid B_q] \le h_SW_R+(\delta_q-h_S)(W_C+W_R)p_q. \tag{60} Tail independence removes the tail increment as q\to0 for fixed bounded allocated quantities. The remaining reserve term is zero when h_SW_R=0. Settlement and encumbrance changes are separate from this frozen-allocation bound.

Proof. Outside A_q, collateral shortfall is zero and reserve loss is at most h_SW_R. Inside A_q, their sum is at most h_SW_R+(\delta_q-h_S)(W_C+W_R). Conditional expectation on B_q gives (60). ◻

11.2 Insurance-fund floor under exogenous-first drain priority

Theorem 11.2 is structural: the clearing layer is denominated in S. The waterfall’s drain order is a separate, procedural choice, and it matters: an endogenous-first absorption discipline re-introduces price coupling through the absorption order even under exogenous denomination. We fix the drain order and prove an unconditional pathwise floor on the exogenous tranche and a conditional monotonicity statement for the whole fund under an explicit price assumption.

The buyback considered later can accumulate hub-asset inventory alongside protected settlement cash. That inventory counts at zero toward the stated default-capacity requirement. The following accounting uses the lower of spot price and time-weighted average price (TWAP) to mark it. The draw sequence keeps this inventory separate from the primary cash tranche.

Definition 11.9 (Exogenous-first drain priority).

Let the insurance fund decompose into an exogenous tranche of settlement-asset value E(b) and an endogenous (hub-asset-denominated) tranche of value R(b) = q_M(b)\cdot P_M(b), where q_M(b) is the hub-asset balance and P_M(b) the spot price marked at the conservative \min(\text{spot}, \text{TWAP}) rule. The hub-asset tranche is what the buyback of Definition 11.13 accumulates; it counts at zero toward the default capacity of Definition 11.1(a) and is drawn last. The waterfall executes exogenous-first when, given a per-block insurance shortfall \Delta(b) \geq 0 (the residual entering insurance after the preceding waterfall stages), the absorption sequence is s_E(b) \;=\; \min(\Delta(b),\, E(b)), \qquad s_R(b) \;=\; \min(\Delta(b) - s_E(b),\, R(b)), \tag{61} i.e. E is consumed before R in every absorption event.

Theorem 11.10 (Exogenous-tranche floor; conditional fund monotonicity).

Suppose the clearing layer is denominated in S (Definition 11.1), the waterfall executes exogenous-first (Definition 11.9), and the per-block shortfall satisfies \Delta(b) \leq E(b). Let \delta_{\mathrm{fee}}(b) \geq 0 be the per-block fee accrual into the fund, paid in S.

(i)

Pathwise floor (unconditional). E(b+1) = E(b) - s_E(b) + \delta_{\mathrm{fee}}(b) \geq E(b) - s_E(b): the post-draw exogenous tranche is a deterministic function of E(b) and the realised shortfall alone, invariant to every realisation of P_M(b+1).

(ii)

Conditional monotonicity (under a named assumption). Assume additionally

  • \mathbb{E}[P_M(b+1) \mid \mathcal{F}_b] \geq P_M(b) — the hub price is a conditional submartingale over the block.

Then the fund value F(b) = E(b) + R(b) satisfies \mathbb{E}\!\left[F(b+1)\,\middle|\,\mathcal{F}_b\right] \;\geq\; F(b) \;-\; \Delta(b) \;+\; \mathbb{E}\!\left[\delta_{\mathrm{fee}}(b)\,\middle|\,\mathcal{F}_b\right], \tag{62} and in the sizing regime \mathbb{E}[\delta_{\mathrm{fee}}] \geq \mathbb{E}[\Delta] the fund is non-decreasing in expectation.

(iii)
Scope. Assumption (H) fails in the cascade regime of §9, where the hub price declines in conditional expectation. There, only the floor (i) survives — and it is the floor, not the expectation statement, that the circuit-breaker of Remark 11.12 consumes.

Proof. (i) E is denominated in S, so \partial_{P_M} E = 0 by Definition 11.1; the sequence (61) gives E(b+1) = E(b) - s_E(b) + \delta_{\mathrm{fee}}(b) with no P_M-dependent term.

(ii) \Delta(b) \leq E(b) forces s_R(b) = 0, hence q_M(b+1) = q_M(b) and \mathbb{E}[R(b+1) \mid \mathcal{F}_b] \;=\; q_M(b)\cdot \mathbb{E}[P_M(b+1) \mid \mathcal{F}_b] \;\geq\; q_M(b)\cdot P_M(b) \;=\; R(b) by (H). Adding the exogenous component from (i) and using s_E(b) \leq \Delta(b) gives (62).

(iii) is a restatement of Theorem 9.6: on the supercritical declining branch, P_M falls and (H) is false; (i) used no price assumption and stands. ◻

Remark 11.11 (Composition with the buyback gate).

Theorem 11.10 applies before a buyback changes inventory. For an actual cash debit c_b and credited hub quantity q_b, the funded update is E(b+1)=E(b)-s_E(b)-c_b+\delta_{\mathrm{fee}}(b). The order of waterfall draws and buyback reservation uses one funded snapshot. At a fixed independent mark p_b, the buyback changes marked value by q_bp_b-c_b. Execution costs and conditional fill selection therefore enter the expectation calculation. Assumption (H) for a fixed quantity alone does not establish a nonnegative expected return on the selected purchase. Definition 11.15 supplies the joint fill, cost, and exit-value contract for that return. Proposition 11.14 preserves the protected cash target using the all-in reservation. Proposition 11.16 supplies its separate pre-action-value depeg comparison.

In the operational threshold below, \mathrm{OI} denotes open interest, the outstanding position notional used by the recorded coverage rule. The parameter \rho_{\min} is its required exogenous-cash ratio. It is a policy ratio, distinct from the feedback coefficient \varrho.

Remark 11.12 (Operational form).

The pathwise floor of Theorem 11.10(i) is what the halt condition consumes: when the waterfall exits the exogenous draw with E(b+1) < \rho_{\min}\cdot \mathrm{OI}(b+1), the exogenous circuit-breaker fires and new position creation is blocked. The conditional form (62) pins the sizing target \mathbb{E}[\delta_{\mathrm{fee}}] \geq \mathbb{E}[\Delta] for a funded steady state.

11.3 Residual risks and the counter-cyclical buyback

The settlement discipline of Definition 11.1 removes the specified clearing-withdrawal channel. Four residual channels remain: (i) position losses on M-exposed positions, absorbed by the waterfall (Theorem 11.2); (ii) holdings and funding links between spoke assets (bounded by Theorem 8.4); (iii) settlement-asset depeg, correlated or not (Section 12 and Corollary 11.8); (iv) governance misconfiguration (structural, outside the model’s scope).

A counter-cyclical buyback purchases the hub asset with funded cash above the protected coverage target. The hub inventory counts at zero toward default capacity under Definition 11.9. The purchase uses an all-in debit reservation, a current physical-risk decision, and current legal eligibility. The next definition states these conditions and records actual fills and costs.

Definition 11.13 (Funded counter-cyclical buyback).

At decision time t, let \mathcal F_t contain the observations available to the action selector. Let E_t be the primary-settlement cash remaining after reservations and commitments outside the protected fund target. Let T_t=\mu_{\mathrm{target}}\mathrm{IF}_{\min,t} be that target, with \mu_{\mathrm{target}}>1 and the scenario-based minimum of Proposition 6.5. For more general fund assets, compute the target from the direct stressed-availability tests of Definition 6.2. An action a specifies a set \Xi_a of permitted partial and terminal fills, costs, and stressed post-action states. Recompute the protected target T_t^{\mathrm{post}}(a,\xi) from the complete stressed post-action portfolio for each \xi\in\Xi_a. Admission requires the joint credit tests of Definition 6.2 and the currency and deadline tests of Definition 6.6 along every permitted path. It also requires \inf_{\xi\in\Xi_a}\{E_t-c(a,\xi)-T_t^{\mathrm{post}}(a,\xi)\}\ge0. A sufficient certificate is c_{\max}+\sup_{\xi\in\Xi_a}T_t^{\mathrm{post}}(a,\xi)\le E_t. The same funding and asset quantities appear once in these tests. An amount appears in either the outside reservations or T_t, once. Let F_t^{\mathrm{mark}} be the recorded pre-action marked fund value and m_t its existing hub-asset inventory. The hub inventory counts at zero toward default capacity under Definition 11.9. For r\in(0,1), the maximum all-in cash budget is B_t=\mathbf1_{G_t}\,r(E_t-T_t)_+. \tag{63} The decision-time gate G_t requires the reserve screen E_t/F_t^{\mathrm{mark}}\geq X, the conditional risk budget in Proposition 11.17, the chosen executable-value budget in Definition 11.15, the post-action resource certificates above, and current action eligibility. The denominator must be positive. A quote or program certifies an all-in debit bound c_{\max}\leq B_t, including fees and worst permitted execution costs. The ledger reserves c_{\max} before dispatch and validates current target, funding, and legal generation atomically. Actual settled quantity q_t and debit c_t update E_t'=E_t-c_t,\qquad m_t'=m_t+q_t. Partial receipts consume the same reservation cumulatively. Terminally unspent capacity is released only after no-effect completion or fenced cancellation. A provider debit beyond its contract is recorded as an actual effect with the resulting deficit and recovery obligation. An unforeseen target increase is recorded as a new shortfall and invokes the retained-margin and funding response. It is not treated as a target that the earlier fill preserved.

Proposition 11.14 (Protected cash and actual execution value).

If the admitted provider contract gives 0\leq c_t\leq c_{\max}\leq B_t and E_t\geq T_t, then E_t'\geq T_t. At a fixed independent accounting mark p_t, the fund’s marked-value change from the executed quantity is \Delta F_t^{\mathrm{mark}}=q_tp_t-c_t. For a constant-product purchase with curve input b, reserves (R_S,R_M), and additional fee f, q_t=\frac{R_Mb}{R_S+b},\qquad c_t=b+f. At the pre-trade mark p_t=R_S/R_M, its marked-value loss is b^2/(R_S+b)+f. An unfilled action records its actual fees and zero acquired inventory.

Proof. The debit is at most r(E_t-T_t)\leq E_t-T_t. The additional admission inequality gives E_t-c(a,\xi)\ge T_t^{\mathrm{post}}(a,\xi) for every permitted outcome. Cash and settled inventory conservation give the marked-value identity. Substitute the constant-product proceeds formula and the pre-trade mark. A failed fill supplies no quantity to the inventory term. ◻

The protected-cash condition asks whether the purchase preserves funding for obligations. The value certificate asks whether its selected fills and later exits satisfy the chosen return budget under the covered laws. Here \mathcal P_t denotes the covered set of current conditional physical laws for these joint execution outcomes.

Definition 11.15 (Executable-value certificate).

The physical scenario contract for an action a specifies joint fills, fees, execution failure, market response, and later exit conditions. Let V_h^a(m+q_a) be net realizable value of the resulting total inventory at horizon h. Let V_h^0(m) be its no-action counterpart under the same exogenous scenario. Both include exit slippage, fees, and the action’s effect on existing inventory. A risk budget R_t^{\mathrm{buy}}\geq0 requires \inf_{P\in\mathcal P_t} \mathbb{E}_P[V_h^a(m+q_a)-V_h^0(m)-c_a\mid\mathcal F_t] \geq-R_t^{\mathrm{buy}}. The case R_t^{\mathrm{buy}}=0 admits a nonnegative expected incremental executable value under every covered law. This value certificate is separate from the shortfall-probability gate. Actual receipts and obligations determine accounting even when the outcome is adverse.

The closed-form sufficient bounds below make the gate’s dependence on the underlying risk parameters explicit.

The reserve threshold X limits the cash that a purchase can spend while preserving a stated depeg allowance. The next horizon threshold Y limits the selected action’s adverse-event probability. Their certificates answer different questions and apply together with the execution and value conditions.

This proposition uses \mathrm{IF}=F_t^{\mathrm{mark}} for the total fund value at its fixed pre-action mark. That valuation book is distinct from the eligible funded default capacity denoted by \mathrm{IF} in the waterfall. Every fraction and amount in this reserve-ratio comparison uses the same valuation book. Its notation \operatorname{VaR}_{1-q} uses a confidence-level subscript, meaning the upper quantile at cumulative probability 1-q. This is the quantile denoted \mathrm{VaR}_q under the tail-mass convention in Definition 4.2.

Proposition 11.16 (Closed-form bound on X).

Let \eta_{\mathrm{safe}} > 0 be a margin-of-safety parameter and q \in (0, 0.05] a tail probability for correlated depegs of the settlement basket. Let h_{\mathrm{stress}}(q):=\operatorname{VaR}_{1-q}(D_{\mathrm{joint}})\in(0,1) be the stressed haircut, where D_{\mathrm{joint}} is the joint depeg magnitude of the other settlement assets against S under the marginal-plus-copula law of Section 12. Let \omega_{\mathrm{non}\text{-}S} := \mathrm{IF}_{\mathrm{non}\text{-}S}/\mathrm{IF} \in [0, 1] be the fund fraction held in those assets, and f_{\min} \in [0, 1) a structural floor on the fraction of the fund held in S. Assume (1+\eta_{\mathrm{safe}})h_{\mathrm{stress}}(q)\omega_{\mathrm{non}\text{-}S}+f_{\min}\leq1-r, so that a threshold X\in[0,1] can satisfy the following condition. Interpret \mathrm{IF} and the other-settlement holdings below at the pre-action valuation, with \mathrm{IF}_S=E_t. If X \;\geq\; \frac{(1 + \eta_{\mathrm{safe}})\, h_{\mathrm{stress}}(q)\, \omega_{\mathrm{non}\text{-}S} \;+\; f_{\min}}{1 - r}, \tag{64} then every admitted execution with all-in debit c_t\leq B_t satisfies E_t-c_t \;\geq\; f_{\min}\,\mathrm{IF} \;+\; (1 + \eta_{\mathrm{safe}})\, h_{\mathrm{stress}}(q)\, \omega_{\mathrm{non}\text{-}S}\,\mathrm{IF}: it keeps the stated amount-based floor and covers the (1-q) depeg-quantile mark-down of the other settlement holdings with margin (1 + \eta_{\mathrm{safe}}). If the feasibility condition fails, no X\in[0,1] satisfies (64). The right-hand side is increasing in the stressed haircut, the non-primary fraction, the safety margin, the floor, and the buyback fraction, and decreasing in q.

Proof. Use E_t, F_t^{\mathrm{mark}}, and the other-settlement holdings at the recorded pre-action valuation. The all-in debit obeys c_t\leq B_t\leq rE_t. Hence E_t-c_t\geq(1-r)E_t\geq(1-r)X F_t^{\mathrm{mark}}. Substitution of (64) gives the stated pre-action-value floor and depeg allowance. The marked fund value need not remain constant after execution. A new valuation or changed target requires the corresponding updated funding test. The quantile h_{\mathrm{stress}}(q) is nonincreasing as the upper-tail mass q increases. ◻

Proposition 11.17 (Decision-time horizon risk gate).

Fix W\geq1, tail budget q\in(0,1), and an action a_t measurable in \mathcal F_t. For each offset j\in\{1,\ldots,W\}, let B_{t,j}(a_t) be the specified adverse event under that action. A current physical-law certificate supplies \bar p_{t,j}(a_t)\geq\Pr(B_{t,j}(a_t)\mid\mathcal F_t). The gate admits only if \sum_{j=1}^W\bar p_{t,j}(a_t)\leq q. Then its conditional probability of any adverse event over the horizon is at most q. If every bound is at most 1-Y, a sufficient common threshold is Y\geq1-q/W. \tag{65} A directly certified bound on the horizon union can replace the sum. All certificates and the action selection use current information, including any lagged feature only through its current predictive law.

Proof. Apply the conditional union bound given \mathcal F_t to the selected action. The gate is measurable in that same information set, so its decision does not introduce future conditioning. Bounding every term by 1-Y gives W(1-Y)\leq q. ◻

Remark 11.18 (Adaptive actions and calibration failure).

Let A_t be the \mathcal F_t-measurable authorization indicator. Across adaptive decisions, the probability of any authorized adverse event is at most \mathbb{E}\sum_t A_tq_t. This follows by conditioning each authorized event on \mathcal F_t and then applying the union bound. A delayed fill indicator X_t can replace A_t in that expectation only under the stronger joint certificate \Pr(B_t\cap\{X_t=1\}\mid\mathcal F_t) \le q_t\Pr(X_t=1\mid\mathcal F_t). Here B_t is the selected horizon adverse event. This additional condition controls adverse selection into actual fills. Add the claimed total certificate-failure probability when the bounds hold only on a coverage event. The union bound requires no independence between future offsets. A recovery-probability bound alone gives no expected-profit guarantee. Definition 11.15 evaluates the joint execution and exit law separately.

A first-order autoregressive process, abbreviated AR(1), carries part of its current deviation into the next observation and adds an innovation. The next bound controls this persistence over a lag. The prediction result that follows also accounts for uncertainty accumulated while an observation becomes stale.

Proposition 11.19 (Closed-form bound on \Delta_{\mathrm{lag}}).

Assume \varrho_t is an AR(1) process with autocorrelation timescale \tau_\varrho> 0 and \varepsilon_{\mathrm{dec}} \in (0, 1) a residual-correlation tolerance. A sufficient lag is \Delta_{\mathrm{lag}} \;\geq\; -\tau_\varrho\, \log \varepsilon_{\mathrm{dec}}. \tag{66} For \varepsilon_{\mathrm{dec}} = 0.05, \Delta_{\mathrm{lag}} \geq 3\tau_\varrho.

Proof. An AR(1) process has autocorrelation e^{-k/\tau_\varrho} at lag k. Requiring e^{-\Delta_{\mathrm{lag}}/\tau_\varrho} \leq \varepsilon_{\mathrm{dec}} gives (66). ◻

Remark 11.20 (Linear autocorrelation vs. concentration tail).

Eq. (66) bounds the linear autocorrelation of \varrho_t at lag \Delta_{\mathrm{lag}}, which is what the AR(1) moment estimator directly consumes; it does not by itself bound the probability that an adversarial innovation sequence carries the lag-window average past the gate. What finite variance delivers is a Chebyshev bound. For a stationary AR(1) with variance \sigma_\varrho^2 and \phi := e^{-1/\tau_\varrho} \in [0, 1), the window average \bar\varrho_n over n blocks has \begin{aligned} \mathop{\mathrm{Var}}(\bar\varrho_n) &=\frac{\sigma_\varrho^2}{n^2}\Bigl(n+2\sum_{h=1}^{n-1}(n-h)\phi^h\Bigr) \leq\frac{\sigma_\varrho^2}{n}\frac{1+\phi}{1-\phi},\\ \mathbb{P}\bigl(|\bar\varrho_n-\mathbb{E}\bar\varrho_n|\geq a\bigr) &\leq\frac{\sigma_\varrho^2}{na^2}\frac{1+\phi}{1-\phi}. \end{aligned} An exponential tail needs a moment-generating-function assumption on the innovations. With independent centred \sigma_\varepsilon^2-sub-Gaussian innovations in the stationary AR(1) solution, \bar\varrho_n - \mathbb{E}\bar\varrho_n = n^{-1}\sum_s c_s\varepsilon_s with 0 \leq c_s \leq 1/(1 - \phi) and \sum_s c_s = n/(1 - \phi), hence \sum_s c_s^2 \leq n/(1 - \phi)^2 and \mathbb{P}\bigl(|\bar\varrho_n - \mathbb{E}\bar\varrho_n| \geq a\bigr) \;\leq\; 2\exp\!\Bigl(-\frac{n\,(1 - \phi)^2\, a^2}{2\sigma_\varepsilon^2}\Bigr), an exponent linear in the window length for a fixed deviation. Neither finite variance nor autocorrelation decay alone delivers this; the sub-Gaussian innovation is the extra assumption.

Here r_s denotes the physical coefficient being forecast for the threshold-one adverse event. It is a scalar forecasting process specified by the following conditional model. Using it to forecast the economic coefficient \varrho_s requires that identification in the calibration certificate.

Proposition 11.21 (Lag, forecast uncertainty, and current selection).

Suppose the physical coefficient follows r_{s+1}=\mu+\phi(r_s-\mu)+\epsilon_{s+1} with 0\leq\phi<1. Conditional on the actual decision information \mathcal F_t, represent r_t=m_t+e_t+Z_t, where |e_t|\leq b_t and Z_t is centered v_t-sub-Gaussian. For future steps, let \mathcal H_s contain \mathcal F_t, the initial error variables Z_t,e_t, and innovations through time s. Require \mathbb{E}[\exp(u\epsilon_{s+1})\mid\mathcal H_s]\le\exp(u^2\sigma^2/2) \quad(u\in\mathbb{R}). Thus the innovation bound holds after the latent current state and each preceding innovation are included. Then at offset j the mean, variance allowance, and bias allowance are \begin{aligned} m_{t,j}&=\mu+\phi^j(m_t-\mu),\\ v_{t,j}&=\phi^{2j}v_t+\sigma^2\frac{1-\phi^{2j}}{1-\phi^2}, \qquad b_{t,j}=\phi^j b_t. \end{aligned} For 1-m_{t,j}-b_{t,j}>0 and v_{t,j}>0, \Pr(r_{t+j}\geq1\mid\mathcal F_t) \leq\exp\!\left[-\frac{(1-m_{t,j}-b_{t,j})^2}{2v_{t,j}}\right]. Use the trivial bound one when the positive-gap condition fails. A zero-variance certificate gives its deterministic bound.

Proof. Unroll the AR(1) recursion. The initial uncertainty has coefficient \phi^j, and future innovation coefficients form a geometric sequence. Iterating the conditional moment-generating-function bounds gives the stated variance allowance. Chernoff optimization gives the one-sided tail bound after adding the worst bias. ◻

Remark 11.22 (A stale feature can have lower correlation and higher risk).

With only a lag-d observation and a valid current conditional model, propagating it adds \sigma^2(1-\phi^{2d})/(1-\phi^2) innovation variance. Its old measurement bias attenuates by \phi^d. For \mu=0.9, \phi=0.8, old coefficient 0.6, and \sigma=0.1, the next-step tail bound rises from approximately 0.00309 at d=0 to 0.540 at d=5. Lag correlation simultaneously falls to 0.32768. Fresh cash or market observations used to select the action belong in \mathcal F_t. An older-filtration calibration cannot be substituted without a current conditional certificate.

Remark 11.23 (Closed-form versus simulation-based gating).

The reserve, horizon-risk, and lag bounds are conditional on their recorded funding and physical-law contracts. A simulation supplies a reproducible conditional comparison of those contracts. Held-out outcomes assess calibration, execution costs, failures, and realized shortfalls. The deterministic synthetic study distinguishes known generator probabilities from empirical deployment evidence.

12 Multi-Settlement-Asset Haircut Model

Theorem 11.2 assumes a single exogenous settlement asset. A CCP can instead accept several eligible settlement assets to reduce single-issuer concentration. The eligibility test remains separate from the exogeneity assumption and must address the PFMI guidance for stablecoin arrangements [36]. This section gives the multi-asset haircut model and proves the bounded-contagion theorem.

12.1 Haircut schedule and depeg isolation

Definition 12.1 (Haircut schedule).

Each accepted settlement asset s \in \mathcal{S} carries a haircut h_s \in [0, 1). Effective collateral in s is C_s^{\mathrm{eff}} = (1 - h_s)\cdot C_s \cdot P_s^{\mathrm{ref}}, with P_s^{\mathrm{ref}} a median-of-oracles reference price.

In Definition 12.1, C_s denotes asset quantity and multiplication by P_s^{\mathrm{ref}} converts it to the common numeraire. For the following monetary loss bounds, C_s denotes that pre-depeg reference value. The per-asset equity and insurance balances likewise denote pre-depeg values in the same numeraire. Thus each depeg fraction multiplies a monetary exposure exactly once.

Proposition 12.2 (Single-asset depeg: price isolation, not loss isolation).

Suppose a realised scenario has asset s^* depegging by magnitude \delta_{s^*} > h_{s^*} while every other settlement asset keeps its reference price. Let E_{\mathrm{SIG},s^*} and \mathrm{IF}_{s^*} be the CCP-equity and insurance-fund balances held in s^*. The clearing-layer loss is bounded by \mathcal{L}_{\mathrm{indep}} \;\leq\; (\delta_{s^*} - h_{s^*})_+\, C_{s^*}+\delta_{s^*}\bigl(E_{\mathrm{SIG},s^*}+\mathrm{IF}_{s^*}\bigr). \tag{67} The depeg marks only collateral, CCP equity, and insurance-fund balances held in s^*: positions denominated in other assets carry no direct depeg mark. This is price isolation. It is not loss isolation. Any residual beyond a defaulter’s collateral is allocated through the shared waterfall of §6.2, which can charge otherwise unaffected members.

Proof. Haircut-adjusted collateral covers the first h_{s^*} of depeg; residual (\delta_{s^*}-h_{s^*})_+C_{s^*} is the unhedged collateral loss. The CCP-equity and fund balances held in s^* lose \delta_{s^*}(E_{\mathrm{SIG},s^*}+\mathrm{IF}_{s^*}). Adding the pathwise losses gives (67). The realised price shock affects only s^*; the waterfall can allocate its residual across other members. ◻

Remark 12.3 (Oracle-synchrony assumption).

Proposition 12.2 assumes the reference-median oracle P_s^{\mathrm{ref}} is synchronous with the depeg event. In practice the oracle updates on a discrete schedule with lag \tau_O > 0; during [t,t+\tau_O] the posted haircut reflects the pre-depeg price while realised collateral, CCP equity, and fund values follow the depegged price. If the depeg path is absolutely continuous, the bound (67) can understate the instantaneous loss during that window by at most \tau_O\sup_s|\dot\delta_s|(C_{s^*}+E_{\mathrm{SIG},s^*}+\mathrm{IF}_{s^*}). A depeg-detection circuit breaker bounds this slippage outside the haircut model; the per-asset bound holds at oracle-update time.

12.2 Correlated depegs and the copula bound

Independence is an idealization; banking-crisis, regulatory-action, and custody-failure channels correlate stablecoin depegs. We give a copula-based upper bound.

Each marginal law describes one settlement asset’s depeg magnitude. The copula supplies their dependence after those marginal laws are fixed. Both determine the distribution of the largest simultaneous depeg used in the bound.

Theorem 12.4 (Correlated-depeg tail loss).

Let \mathcal{K}\subseteq \mathcal{S} be the set of simultaneously depegging assets under a correlated-stress scenario with depeg magnitudes \{\delta_k\}_{k \in \mathcal{K}} drawn from a joint distribution with copula \mathsf{C}. Let C_k be total posted collateral held in settlement asset k. Let E_{\mathrm{SIG},k} and \mathrm{IF}_k be the per-asset CCP-equity and insurance-fund balances, with \sum_kE_{\mathrm{SIG},k}=E_{\mathrm{SIG}} and \sum_k\mathrm{IF}_k=\mathrm{IF}. At tail probability q, the clearing-layer loss satisfies \mathop{\mathrm{ES}}_q[\mathcal{L}_{\mathrm{corr}}] \;\leq\; \sum_{k \in \mathcal{K}} C_k\,\mathop{\mathrm{ES}}_q\bigl[(\delta_k - h_k)_+\bigr]\;+\;\delta_q^{\mathrm{tail}}\bigl(E_{\mathrm{SIG}}+\mathrm{IF}\bigr), \tag{68} where \delta_q^{\mathrm{tail}} := \mathop{\mathrm{ES}}_q[\max_{k \in \mathcal{K}}\delta_k] is the joint-tail magnitude. The collateral terms are marginal quantities of the single-asset depeg laws; \delta_q^{\mathrm{tail}} is a functional of the joint law, the marginals together with \mathsf{C} [10, 11], and is not determined by the copula or by pairwise tail-dependence coefficients alone.

Proof. The loss has two channels, and pathwise \mathcal{L}_{\mathrm{corr}}\leq\sum_{k\in\mathcal{K}}C_k(\delta_k-h_k)_+ +\sum_{k\in\mathcal{K}}\delta_k(E_{\mathrm{SIG},k}+\mathrm{IF}_k) \leq\sum_{k\in\mathcal{K}}C_k(\delta_k-h_k)_+ +(E_{\mathrm{SIG}}+\mathrm{IF})\max_{k\in\mathcal{K}}\delta_k. For collateral, the haircut absorbs the first h_k of each depeg. The CCP-equity and fund holdings reprice without that collateral haircut. Expected Shortfall is monotone, subadditive, and positively homogeneous [60]; applying it to the pathwise bound gives (68). ◻

Corollary 12.5 (Settlement-basket valuation).

For a basket satisfying Definition 11.1, fixed settlement quantities have no direct hub-price revaluation. Theorem 12.4 bounds shortfall against haircut-adjusted collateral credit together with the mark-down of unhaircut reserves. Direct collateral valuation changes equal the depeg times the pre-depeg reference value. Subsequent settlements and encumbrances change drawable capacity through the deduction in Corollary 11.7. The ADL component consists of position-profit claims and retains its mark dependence.

Remark 12.6 (Diversification bounds).

Let \mathcal{S}_{\mathrm{stable}} be the issuer-backed settlement-asset subset and assume the non-stable reserve is disjoint from it. For a depegging set \mathcal{K}\subseteq\mathcal{S}_{\mathrm{stable}}, require (i) \mathrm{IF}_k\leq\omega_{\max}\mathrm{IF} for each issuer and (ii) \mathrm{IF}_{\mathrm{non-stable}}\geq\omega_{\min}\mathrm{IF}. Then \sum_{k\in\mathcal{K}}\mathrm{IF}_k \leq\min\{|\mathcal{K}|\omega_{\max},1-\omega_{\min}\}\mathrm{IF}. The fund mark-down in Theorem 12.4 therefore gains the same multiplicative factor. The reserve floor gives no such bound if \mathcal{K} is allowed to include assets counted in the non-stable reserve. The cap and floor bound the same sum and do not compound. Open Problem 1 asks how to choose them.

13 Adversarial Bounds

For each defense in the preceding sections, this section fixes an adversary model, proves an upper bound on the adversary’s payoff, and, where the model admits it, constructs an attack that matches the bound. One-sided bounds are marked as such in Table 2.

13.1 Adversary catalogue

We distinguish four baseline adversary classes used below.

A Sybil strategy divides one controller’s activity among several accounts. The model charges a separate know-your-customer (KYC) identity cost for each account. The classes below distinguish how many accounts, observations, and event outcomes the adversary can control.

Definition 13.1 (Adversary classes).

(a)

Rational single-account adversary \mathcal{A}_{\mathrm{RS}}: a single account chooses a portfolio and trade sequence to maximise expected net profit, subject to the margin rules of §3 and the waterfall of §6. Non-adaptive within a block: chooses an action once per clearing step given public state.

(b)

Sybil-Rational multi-account adversary \mathcal{A}_{\mathrm{SR}}(K): controls K distinguishable accounts, each facing its own margin and KYC cost c_{\mathrm{KYC}}. Collusion across accounts is free. Non-adaptive within a block.

(c)

Adaptive multi-block adversary \mathcal{A}_{\mathrm{AM}}(T): chooses actions block-by-block over horizon T, observing all public state at each block including realised prices, oracle feeds, and insurance-fund balance. Strategy may condition on history.

(d)

Correlated-event adversary \mathcal{A}_{\mathrm{CE}}: controls both a portfolio and, at cost c_{\mathrm{ev}}, the realisation of a single event outcome (or a correlated bundle) used as oracle input by the clearing layer.

All classes are computationally unbounded in the information-theoretic sense; all gains and costs are measured in the exogenous settlement asset S.

13.2 Reflexivity rate-limiter and adaptive-oscillation bound

Theorem 11.2 removes the primary reflexive channel when the clearing layer is denominated in S. An exchange-level control may nonetheless expose a residual reflexive channel through a policy parameter \Phi(t) (for example, an LP-fee tilt or a dynamic haircut) whose movement induces cross-pool liquidity reallocation. We model this residual channel and prove that a rate-limiter on \Phi caps the amplitude of any adaptive adversarial oscillation.

Definition 13.2 (Policy-driven reflexivity proxy).

Fix \Phi: \mathbb{R}_{\geq 0} \to \mathbb{R} a scalar policy process with |\Phi(t)| \leq \Phi_{\max}. The policy-reflexivity proxy is \varrho_{\Phi}(t) \;:=\; \frac{\lambda_{\Phi}\, L(t)\, \partial_\Phi f(L(t), \Phi(t))}{P_M(t)}, with \lambda_\Phi > 0 a dimensionless policy LP elasticity. This is the policy analogue of \varrho_{\mathrm{LP}} in Definition 9.3; the clearing-layer component is absent because Theorem 11.2 has already set \Gamma = 1. \varrho_\Phi measures the instantaneous sensitivity of locked liquidity to \Phi.

Definition 13.3 (Rate-limiter).

A rate-limiter with cap \delta_\Phi > 0 imposes |\Phi(b+1)-\Phi(b)|\leq\delta_\Phi at every block boundary b. For analysis, time is measured in blocks and the protocol uses the piecewise-linear interpolation between boundary values. Thus \Phi is absolutely continuous, |\dot\Phi(t)|\leq\delta_\Phi almost everywhere, and |\Phi(t)|\leq\Phi_{\max}.

Proposition 13.4 (Amplitude bound under rate-limiter; upper and lower).

Let x(t):=\varrho_\Phi(t)-\bar\varrho and suppose the response about the equilibrium is the stable first-order system \dot x(t)=-\kappa x(t)+g_\Phi\dot\Phi(t), \qquad x(0)=0, \tag{69} where \kappa>0 is the decay rate and g_\Phi\geq0 is the policy sensitivity. For every \mathcal{A}\in\mathcal{A}_{\mathrm{AM}}(T) subject to Definition 13.3, \sup_{0\leq t\leq T}|x(t)| \;\leq\; \frac{g_\Phi\delta_\Phi}{\kappa}\bigl(1-e^{-\kappa T}\bigr) \;\leq\; \frac{g_\Phi\delta_\Phi}{\kappa}. \tag{70} If T\delta_\Phi\leq\Phi_{\max}-|\Phi(0)|, a constant-sign maximal-rate input, \dot\Phi(t)=\pm\delta_\Phi, attains the first right-hand expression at t=T. Thus the finite-horizon bound is exact under (69). Any independently proved pathwise cap on |x| can be intersected with this bound.

Proof. Variation of constants gives x(t)=g_\Phi\int_0^t e^{-\kappa(t-s)}\dot\Phi(s)\,ds. The rate cap therefore gives |x(t)|\leq g_\Phi\delta_\Phi(1-e^{-\kappa t})/\kappa. This expression is increasing in t, proving (70). If \dot\Phi has constant sign and magnitude \delta_\Phi, equality holds in the integral. The stated range condition keeps that input admissible through T. ◻

Remark 13.5 (Design-time choice of \delta_\Phi).

Equation (70) converts the rate-limiter cap \delta_\Phi into a deterministic amplitude bound. Given a maximum tolerated amplitude \bar A<1-\bar\varrho, the sufficient infinite-horizon condition is \delta_\Phi\leq\kappa\bar A/g_\Phi when g_\Phi>0. The dependence on \delta_\Phi is exact while the policy range does not bind.

Remark 13.6 (Limitations of the upper bound).

The bound is conditional on the specified first-order response (69). Its impulse response is the non-negative exponential g_\Phi e^{-\kappa t}, so this model has no oscillatory mode and no resonance. A higher-order, delayed, or nonlinear controller is not covered. Bounding one requires its full input-output operator; for a stable linear system the corresponding rate-input bound uses the induced L^\infty gain, equivalently the L^1 norm of the impulse response. A decay-rate estimate alone does not provide that bound and cannot be called conservative against resonance. Observation error affects an estimator of x, not the deterministic state bound above, and must be added as a separate probabilistic error term under an explicit noise model.

Proposition 13.7 (Size-dependent oscillation-profit bound).

Assume Proposition 13.4. Let q\in(0,q_{\max}] be the total round-trip size of an admitted block action. Suppose its gross captured value is at most \ell_Vq|x(t)|, with \ell_V\geq0. Each leg pays proportional fee f_{\mathrm{AMM}}\geq0. A nonzero block action incurs execution cost at least c_{\mathrm{gas}}\geq0. Define A:=\ell_Vg_\Phi\delta_\Phi/\kappa-2f_{\mathrm{AMM}}. Then \pi_{\mathrm{osc}}(q)\leq qA-c_{\mathrm{gas}}, \qquad \sup_{\text{admitted actions or abstention}}\pi_{\mathrm{osc}} \leq [q_{\max}A-c_{\mathrm{gas}}]_+. \tag{71} Abstention has zero gain and cost. Several trades satisfy this statement when their total size obeys q_{\max} and the stated gain and fee bounds add. The bound permits profitable nonzero actions when the captured-value coefficient exceeds the admitted costs.

Proof. The pathwise gain bound and (70) give gross value at most q\ell_Vg_\Phi\delta_\Phi/\kappa. Subtracting the action’s two proportional fees and execution-cost lower bound proves the first inequality. If A\geq0, its largest right side over q\in(0,q_{\max}] occurs at q_{\max}. If A<0, every nonzero action has a nonpositive right side. Including abstention gives the second inequality in both cases. ◻

Corollary 13.8 (Break-even condition over admitted sizes).

If g_\Phi\ell_V>0 and q_{\max}>0, no admitted block action has positive profit whenever \delta_\Phi \leq \frac{\kappa}{g_\Phi\ell_V} \left(2f_{\mathrm{AMM}}+\frac{c_{\mathrm{gas}}}{q_{\max}}\right). This condition permits a positive policy-rate limit whenever the stated cost allowance is positive.

Proof. The condition is equivalent to q_{\max}A-c_{\mathrm{gas}}\leq0. Apply the optimized bound in (71). ◻

13.3 Gated-buyback manipulation path

Propositions 11.16 and 11.17 bound the funded and physical-risk gates. Proposition 11.19 bounds an auxiliary autocorrelation statistic. A matching manipulation-cost statement needs a complete observation model and the exact reserve-ratio arithmetic. The following model makes both explicit.

This calculation fixes a complete observation model for two diagnostic screens. The symbol \Phi^{-1} below denotes the standard normal quantile function. It is distinct from the policy process \Phi(t) in Section 13.2. Passing these screens leaves the action’s other funding, legal, and physical-risk requirements in force.

Proposition 13.9 (Gaussian diagnostic-screen manipulation cost).

Consider the recorded reserve and recovery-statistic screens as an auxiliary two-screen model. Let n:=\Delta_{\mathrm{lag}}\in\mathbb N, let X,Y\in(0,1) be the two gate thresholds, and let the initial insurance fund have marked value F_0>0 and primary-settlement reserve x_0F_0, x_0\in[0,1). An irrevocable contribution u\geq0 of the primary settlement asset enters both the reserve and total fund value, so the new reserve ratio is (x_0F_0+u)/(F_0+u).

Let a scalar recovery statistic have baseline z_0<Y and displacement state y_{t+1}=\phi y_t+I_t, \qquad y_0=0, \qquad I_t\geq0, \qquad \phi\in[0,1), over t=0,\ldots,n-1. The gate observes z_0+n^{-1}\sum_{t=1}^n y_t+e+Z, where |e|\leq\varepsilon_p and Z\sim N(0,\sigma_{\mathrm{obs}}^2/n). An injection of total size \sum_tI_t costs D_M^{\mathrm{clear}}\sum_tI_t. The contribution u is locked and cannot finance the injections, so the two costs add.

To trigger both gates with probability at least p^\star\in(1/2,1) uniformly over |e|\leq\varepsilon_p, the exact minimum cost is \mathcal{C}_{\mathrm{adv}}^{\min} = \frac{F_0(X-x_0)_+}{1-X} +D_M^{\mathrm{clear}}\,\frac{n(1-\phi)}{1-\phi^n}\,\psi^\star, \qquad \psi^\star:=\left[Y-z_0+\varepsilon_p+\frac{\sigma_{\mathrm{obs}}}{\sqrt n}\Phi^{-1}(p^\star)\right]_+. \tag{72} The minimum is attained by contributing the first term’s required reserve and placing the entire recovery-statistic injection at t=0.

The displayed cost is exact for these two screens under their stated observation law. Passing them is necessary but does not replace the funded execution, current physical-risk, and legal conditions of Definition 11.13.

Proof. The reserve gate requires (x_0F_0+u)/(F_0+u)\geq X, which is equivalent to u\geq F_0(X-x_0)_+/(1-X). For the recovery gate, \frac1n\sum_{t=1}^n y_t =\sum_{j=0}^{n-1}w_jI_j, \qquad w_j:=\frac{1-\phi^{n-j}}{n(1-\phi)}. The weights are non-negative and w_j\leq w_0=(1-\phi^n)/(n(1-\phi)). Thus a total injection I:=\sum_jI_j produces average displacement at most w_0I, with equality when I_0=I and all later injections vanish. Uniformly over |e|\leq\varepsilon_p, the least favourable error is e=-\varepsilon_p. Gaussian inversion then gives the necessary and sufficient displacement \psi^\star for trigger probability p^\star. Hence I_{\min}=\psi^\star/w_0. The locked reserve contribution and injection budget are disjoint by assumption, so their exact minima add. ◻

Remark 13.10 (What sub-Gaussian noise does and does not imply).

Equation (72) uses the Gaussian quantile because the proposition assumes Gaussian noise. A sub-Gaussian proxy supplies an upper-tail inequality, not an inverse Gaussian quantile or a matching necessity statement. Under centred \sigma_{\mathrm{obs}}^2/n-sub-Gaussian noise, the sufficient confidence buffer is \frac{\sigma_{\mathrm{obs}}}{\sqrt n} \sqrt{2\log\!\frac1{1-p^\star}}. It does not prove an exact minimum without a lower-tail assumption.

Corollary 13.11 (Exact persistence multiplier).

The exact multiplier converting a required window-average displacement into the cheapest total injection is n(1-\phi)/(1-\phi^n). It equals one at n=1, tends to n(1-\phi) as n\to\infty, and is attained by front-loading the injection. This statement concerns the specified AR(1) state and linear injection cost; other dynamics require their own impulse-response weights.

13.4 Waterfall attacks

We formalise four attacks against the waterfall of §6.2: hedge-discount leg-removal, synthetic-directional cross-margin, insurance-drain via Sybils, and strategic default. Each is stated with an explicit adversary, payoff bound, and (where possible) matching construction.

13.4.1 Hedge-discount leg-removal

Portfolio-margin computations reward hedges via the correlation-structured formula (3). An adversary may post a hedged pair, collect the margin discount, then remove one leg immediately before a clearing step to capture the discount as profit.

Proposition 13.12 (Hedge-discount attack; bound and Gaussian specialization).

Let \mathcal{A}\in \mathcal{A}_{\mathrm{RS}} post a hedged pair with legs (A, B) of notional Q, standalone margin rates m_A, m_B per unit notional, and correlation \rho_{AB} \geq \rho_0 > 0; under (2) the pair’s margin discount is D(\rho_{AB}) \;:=\; \bigl(m_A + m_B - \sqrt{m_A^2 + m_B^2 - 2\rho_{AB}\, m_A m_B}\bigr)\, Q , which is \bigl(2 - \sqrt{2(1 - \rho_{AB})}\bigr)Q at unit rates. Let \alpha_{\mathrm{lag}} \in [0, 1) be the intra-block recompute lag of the margin system (the fraction of a block during which the unhedged position is not yet re-margined) and let the unhedged leg’s per-unit P&L over the lag, X_s, be a square-integrable martingale with X_0 = 0 and per-block return standard deviation \sigma_B, so that \mathbb{E}X_{\alpha_{\mathrm{lag}}}^2 = \sigma_B^2\alpha_{\mathrm{lag}}. The adversary’s expected gain from removing leg A and running leg B unhedged through the lag, over an honestly margined position of the same size, is the expected loss it walks away from under limited liability out of the collateral it was allowed not to post. Let C_{\mathrm{hon}} and C_{\mathrm{att}} be the collateral actually held after all floors and stress layers for the honest and attacked states, and define the realised collateral reduction d:=\bigl(C_{\mathrm{hon}}-C_{\mathrm{att}}\bigr)_+\leq D(\rho_{AB}). For an exit time \tau\leq\alpha_{\mathrm{lag}}, the exact limited-liability advantage before fees is \mathbb{E}\!\left[(QX_\tau^- - C_{\mathrm{att}})_+-(QX_\tau^- - C_{\mathrm{hon}})_+\right]. It satisfies \pi_{\mathrm{hedge}}(\mathcal{A}) \;\leq\; \min\bigl\{d,\; Q\mathbb{E}X_\tau^-\bigr\}-2f_{\mathrm{AMM}}Q \;\leq\;\min\bigl\{d,\;\tfrac12\sigma_B\sqrt{\alpha_{\mathrm{lag}}}\,Q\bigr\}-2f_{\mathrm{AMM}}Q. \tag{73} For a fixed lag \tau=\alpha_{\mathrm{lag}} with QX_\tau\sim N(0,s^2), define G(C):=s\varphi(C/s)-C\Phi(-C/s), where \varphi and \Phi are the standard normal density and distribution. The exact advantage before fees is G(C_{\mathrm{att}})-G(C_{\mathrm{hon}}). Its supremum over 0\leq C_{\mathrm{att}}\leq C_{\mathrm{hon}} is s/\sqrt{2\pi}, approached as C_{\mathrm{att}}=0 and C_{\mathrm{hon}}\to\infty. This is an exact Gaussian specialization, not a construction attaining the distribution-free bound; a binding margin floor or correlation-stress charge reduces d and the attainable gain.

Proof sketch. Bound. Bounded optional stopping gives \mathbb{E}X_\tau=0, so the attack has no expected trading gain over the honest position before limited liability. For z\geq0 and C_{\mathrm{hon}}\geq C_{\mathrm{att}}, the difference (z-C_{\mathrm{att}})_+-(z-C_{\mathrm{hon}})_+ lies in [0,\min\{d,z\}]. Taking z=QX_\tau^- gives the first inequality in (73). Since \mathbb{E}X_\tau=0, \mathbb{E}\, X_\tau^- \;=\; \tfrac12\,\mathbb{E}\,|X_\tau| \;\leq\; \tfrac12\,\bigl(\mathbb{E}X_\tau^2\bigr)^{1/2} \;\leq\; \tfrac12\,\bigl(\mathbb{E}X_{\alpha_{\mathrm{lag}}}^2\bigr)^{1/2} \;=\; \tfrac12\,\sigma_B\sqrt{\alpha_{\mathrm{lag}}}, the last inequality by optional stopping for the submartingale X^2. Both caps apply; subtracting round-trip AMM fees gives (73).

Gaussian specialization. If Z:=QX_\tau\sim N(0,s^2), direct integration gives \mathbb{E}[(Z^- - C)_+]=s\varphi(C/s)-C\Phi(-C/s)=G(C). Subtracting the two collateral states gives the exact difference. Since G(0)=s/\sqrt{2\pi} and G(C)\downarrow0 as C\to\infty, the stated supremum follows. ◻

Remark 13.13 (Defence: zero-lag re-margining).

The attack is blocked outright by enforcing \alpha_{\mathrm{lag}} = 0: any margin-state transition arising from a leg removal recomputes portfolio margin before the next adversary action becomes valid. The AMM-deterministic price-impact kernel (Assumption 2.1) permits deterministic intra-block re-margining at block finalization, realising \alpha_{\mathrm{lag}} = 0 in the clearing model of §6.

13.4.2 Synthetic-directional via cross-margin

A second hedge-exploit arises when cross-margining across multiple spoke assets lets an adversary assemble a synthetic directional position at a cost below the standalone margin. We bound the advantage.

Proposition 13.14 (Synthetic-directional cross-margin upper bound).

Let \mathcal{A}\in \mathcal{A}_{\mathrm{CE}} correlate the realisation of spoke asset B_j’s event with a pre-positioned portfolio \Pi of spoke assets \{B_{i}\}_{i\neq j}, margined under the parametric model (2) at the pre-event correlation estimate \mathbf{P}_{\mathrm{pre}}, and let \mathbf{P}_{\mathrm{post}} be the correlation matrix realised after the event; both are positive semidefinite, and \mathbf{m} is the vector of standalone margins of (2), signed by position direction so that a hedge enters with opposite signs. The collateral the portfolio was allowed not to post is the margin shortfall \Delta_\rho(\Pi) \;:=\; \Bigl[\sqrt{\mathbf{m}^\top \mathbf{P}_{\mathrm{post}}\, \mathbf{m}} \;-\; \sqrt{\mathbf{m}^\top \mathbf{P}_{\mathrm{pre}}\, \mathbf{m}}\Bigr]_+ , \tag{74} and the adversary’s advantage over an honestly margined position of the same size satisfies \pi_{\mathrm{synth}}(\mathcal{A}) \leq \Delta_\rho(\Pi) - c_{\mathrm{ev}}, where c_{\mathrm{ev}} is the event-manipulation cost of Definition 13.1(d). For a two-leg offset with standalone margins m_A, m_B and return correlation \rho, writing R(\rho) := \sqrt{m_A^2 + m_B^2 - 2\rho\, m_A m_B} as in Proposition 13.12, \Delta_\rho \;=\; \bigl[R(\rho_{\mathrm{post}}) - R(\rho_{\mathrm{pre}})\bigr]_+ \;=\; \frac{2\, m_A m_B\, (\rho_{\mathrm{pre}} - \rho_{\mathrm{post}})_+}{R(\rho_{\mathrm{post}}) + R(\rho_{\mathrm{pre}})} whenever the denominator is positive, so the deficit arises exactly when the legs decorrelate, \rho_{\mathrm{post}} < \rho_{\mathrm{pre}}, and it is not linear in the correlation differential.

At equal legs the differential is m\sqrt{2}\,\bigl(\sqrt{1 - \rho_{\mathrm{post}}} - \sqrt{1 - \rho_{\mathrm{pre}}}\bigr). Its derivative in \rho_{\mathrm{post}}, -m/\sqrt{2(1 - \rho_{\mathrm{post}})}, is unbounded near \rho = 1. For example, \rho_{\mathrm{pre}}=0.9999 and \rho_{\mathrm{post}}=0.99 give \Delta_\rho=m\sqrt{2}\,(0.1-0.01)=0.09\sqrt{2}\,m\approx0.127279m, \qquad |\rho_{\mathrm{pre}}-\rho_{\mathrm{post}}|=0.0099, so \Delta_\rho/|\Delta\rho|\approx12.856m. No global bound linear in |\Delta\rho| with a fixed finite coefficient holds on [-1,1]. The proposition proves only this upper bound.

Proof sketch. The cross-margin the portfolio posts is \sqrt{\mathbf{m}^\top \mathbf{P}_{\mathrm{pre}}\mathbf{m}} by (2), and the margin the realised dependence calls for is \sqrt{\mathbf{m}^\top \mathbf{P}_{\mathrm{post}}\mathbf{m}}; the collateral the adversary was allowed not to post, which under limited liability is the most the strategy can gain over an honestly margined position of the same size (the argument of Proposition 13.12), is the positive part of the difference. The event-manipulation cost c_{\mathrm{ev}} subtracts by Definition 13.1(d). For two legs, R(\rho_{\mathrm{post}})^2 - R(\rho_{\mathrm{pre}})^2 = 2 m_A m_B(\rho_{\mathrm{pre}} - \rho_{\mathrm{post}}), and dividing by R(\rho_{\mathrm{post}}) + R(\rho_{\mathrm{pre}}) gives the closed form. No matching construction is given; the bound is one-sided. ◻

Remark 13.15 (Heuristic attack mechanism).

A trader can pre-position the portfolio and trigger the event that changes its dependence structure. This mechanism may approach the collateral shortfall in (74), less AMM fees and the trigger cost. The paper does not construct an admissible strategy that attains the bound. The attainment claim is therefore heuristic.

Remark 13.16 (Defence: correlation stress set).

Let \mathcal{P}_{\mathrm{stress}}(\mathbf m) be the set of Definition 3.12, containing the post-event dependence the CCP means to cover, and write M(\mathbf{P}) := \sqrt{\mathbf{m}^\top\mathbf{P}\,\mathbf{m}}. Charging M_{\mathrm{req}} \geq \max\{M(\mathbf{P}_{\mathrm{pre}}),\ \sup_{\mathbf{P} \in \mathcal{P}_{\mathrm{stress}}(\mathbf m)} M(\mathbf{P})\} makes the realised collateral deficit zero for every \mathbf{P}_{\mathrm{post}} \in \mathcal{P}_{\mathrm{stress}}(\mathbf m). The diagnostic quantity \Delta_\rho in (74) need not be zero; the stress charge pre-funds it. The stress is on the portfolio margin, not on individual entries. For a hedged pair a lower return correlation is the conservative direction, and \rho = 1 gives the smallest hedge margin, |m_A - m_B|, zero at equal legs; for a same-direction book a higher correlation is conservative, and \rho = 1 restores the isolated margin; and the entrywise maximum or minimum of two correlation matrices need not be positive semidefinite. Let s_i=\mathop{\mathrm{sgn}}(m_i), with any value in \{-1,1\} when m_i=0. The sign matrix \mathbf P^{\mathrm{sign}}=\mathbf s\mathbf s^\top is positive semidefinite and has unit diagonal, so it is a correlation matrix. It gives \sqrt{\mathbf m^\top\mathbf P^{\mathrm{sign}}\mathbf m} =\left|\mathbf s^\top\mathbf m\right|=\sum_i|m_i|. For every correlation matrix \mathbf P, |P_{ij}|\leq1, hence \mathbf m^\top\mathbf P\mathbf m\leq(\sum_i|m_i|)^2. The sign matrix therefore gives the global maximum, the isolated margin. Intermediate PSD stress sets trade capital efficiency against attack surface.

13.4.3 Insurance-fund drain via Sybils

An adversary may open many small accounts and take offsetting positions across them, so that the losing accounts default with losses beyond their collateral while the winning account collects in full, the excess being paid through the post-collateral waterfall. With zero per-account identity cost, the accounting demand can grow with the number of controlled accounts. Actual fund draws require executable offsets, payable winning claims, waterfall eligibility, and available funding.

Proposition 13.17 (Sybil-drain economics).

Let \mathcal{A}\in \mathcal{A}_{\mathrm{SR}}(K + 1) open K losing accounts with collateral C_{\mathrm{per}} each and one winning account. Set E_{\mathrm{SIG}}=0 and isolate the insurance-fund draw from later waterfall stages. Let \mathrm{IF}_0 be the fund immediately before the attack. Each losing account incurs loss (1+\varepsilon)C_{\mathrm{per}}, where 0<\varepsilon\leq\varepsilon_{\max} and \varepsilon_{\max}C_{\mathrm{per}} is the largest one-step loss beyond posted collateral. A protocol cap limits each losing account’s draw to \chi\mathrm{IF}_0 in the epoch. Then the total insurance-fund payout is at most P_{\mathrm{IF}}\leq \min\!\left\{\mathrm{IF}_0,\;K\min(\varepsilon C_{\mathrm{per}},\chi\mathrm{IF}_0)\right\}. \tag{75} With identity cost c_{\mathrm{KYC}} per account, the adversary’s net profit from the fund is at most \min\!\left\{\mathrm{IF}_0,\;K\min(\varepsilon C_{\mathrm{per}},\chi\mathrm{IF}_0)\right\} -(K+1)c_{\mathrm{KYC}}, \tag{76} before trading fees and slippage. The payout upper bound equals the fund balance exactly when K\min(\varepsilon C_{\mathrm{per}},\chi\mathrm{IF}_0)\geq\mathrm{IF}_0, which implies K\geq1/\chi. The threshold c_{\mathrm{KYC}}\geq\min(\varepsilon_{\max}C_{\mathrm{per}},\chi\mathrm{IF}_0) makes the upper bound negative for every K.

Proof. Stage 1 absorbs C_{\mathrm{per}} per losing account. The remaining claim is at most d:=\min(\varepsilon C_{\mathrm{per}},\chi\mathrm{IF}_0) per account. The initial fund caps aggregate payment at \mathrm{IF}_0, which proves (75). Subtracting the cost of K+1 identities proves (76). Saturation of the payout upper bound is equivalent to Kd\geq\mathrm{IF}_0. Since d\leq\chi\mathrm{IF}_0, exhaustion implies K\chi\geq1. Achieving the bound also requires executable offsetting positions whose winner receives every paid claim; the proposition does not infer that construction from the accounting bound. Every actual draw must also satisfy the governing waterfall eligibility and funded-availability conditions. ◻

Remark 13.18 (Defence: identity gating).

The proposition isolates two independent defences. The concentration cap forces at least 1/\chi losing accounts for exhaustion. The identity cost makes the fund-capture upper bound negative when it meets the stated threshold. A large \chi permits a large single-account draw, while zero identity cost admits scale.

13.4.4 Strategic default with friction cost

A rational defaulter may prefer to default and absorb the waterfall consequences if the realised off-exchange P&L exceeds the collateral seized. We account for the off-exchange hedge friction cost.

Proposition 13.19 (Strategic-default profitability condition).

Let \mathcal{A}\in \mathcal{A}_{\mathrm{SR}}(K) hold positions totaling notional Q across K accounts, each with per-account collateral C_{\mathrm{per}}. Let E:=\{|\Delta P|\geq\delta_{\mathrm{default}}\} be the default-triggering event, p_{\mathrm{trigger}}:=\mathbb{P}(E)>0, \mu_{\Delta}:=\mathbb{E}[|\Delta P|\mid E], and b_T:=\mathbb{E}[|B_T|\mid E], where B_T is the cross-exchange hedge-basis error over the holding period. Assume the attack’s gross external payoff on E is Q(|\Delta P|-|B_T|)-C_{\mathrm{off}}(Q,T), and its payoff on E^c is -c_{\mathrm{position}}. The expected net profit after forfeiting collateral on E is \begin{aligned} \mathbb{E}[\pi_{\mathrm{strat}}] &=p_{\mathrm{trigger}}\Bigl(Q\mu_{\Delta}-K C_{\mathrm{per}} -C_{\mathrm{off}}(Q,T)-Qb_T\Bigr)\\ &\quad-(1-p_{\mathrm{trigger}})c_{\mathrm{position}}, \end{aligned} \tag{77} The attack is profitable exactly when the triggering-state bracket exceeds \frac{1-p_{\mathrm{trigger}}}{p_{\mathrm{trigger}}}\,c_{\mathrm{position}}. If B_T is independent of E and Gaussian with standard deviation \sigma_{\mathrm{basis}}, then b_T=\sigma_{\mathrm{basis}}\sqrt{2/\pi}.

Proof. Condition on E and E^c under the stated payoff model. On E, take the conditional expectations of the adverse move and basis error and subtract forfeited collateral and execution cost. The law of total expectation gives (77). The Gaussian special case is the standard identity \mathbb{E}|N(0,\sigma^2)|=\sigma\sqrt{2/\pi}. ◻

Remark 13.20 (Sensitivity of the profitability boundary).

Expected profit in (77) decreases as b_T, C_{\mathrm{off}}(Q,T), or KC_{\mathrm{per}}/Q increases, holding the other quantities fixed. Equivalently, the required adverse move for profitability increases. Tail-shape changes affect both p_{\mathrm{trigger}} and \mu_\Delta; their net effect must be computed from the specified loss law and is not monotone without further assumptions.

13.5 Concurrent defaults in the waterfall

Proposition 6.13 establishes that the waterfall is order-independent under simultaneous defaults when stages are applied level-by-level. We now state the exact loss-absorption limit for one concurrent default set.

Proposition 13.21 (Concurrent-default loss-absorption limit).

Under Theorem 6.12, with \Delta_k := L_k the gross pre-collateral loss of defaulter k, the total absorbable shortfall across any concurrent-default set D \subseteq [K] satisfies \sum_{k \in D} \Delta_k \;\leq\; \sum_{k \in D} C_k + E_{\mathrm{SIG}} + \mathrm{IF} + \textstyle\sum_{k \in \mathcal{B}} a_k + \sum_{k \in \mathcal{P}} \pi_k \;\;\Rightarrow\;\; \Delta^{\mathrm{res}} = 0. \tag{78} The five terms are defaulter collateral, CCP equity, the mutualised insurance fund, mutualised capped socialisation over \mathcal{B}, and ADL profit-claim extinguishment. Each positive defaulter-collateral balance is seized in full. Stages 2–5 can each be saturated exactly in an admissible configuration. If Stage 1 is the only positive layer, however, the zero-residual boundary is approached but not attained because default requires L_k>C_k.

Proof. The implication follows from Theorem 6.12. For any \varepsilon>0, a single account with collateral C>0 and loss C+\varepsilon uses all Stage 1 capacity and leaves \varepsilon for the next layer. Thus Stage 1 is fully drawn, while the Stage-1-only zero-residual boundary is approached as \varepsilon\downarrow0. With zero earlier capacity, losses equal to E_{\mathrm{SIG}}, \mathrm{IF}, \sum_{k\in\mathcal{B}}a_k, or \sum_{k\in\mathcal{P}}\pi_k saturate Stages 2, 3, 4, or 5 respectively. ◻

Corollary 13.22 (Loss-absorption failure frontier).

For a fixed default set D, write \mathcal{C}^{\mathrm{abs}}(D) as in (59). Then \Delta^{\mathrm{res}}(D)=\Bigl(\sum_{k\in D}\Delta_k-\mathcal{C}^{\mathrm{abs}}(D)\Bigr)_+. A positive residual occurs exactly when the concurrent loss exceeds every available stage. For fixed D, \mathcal{B}, and \mathcal{P}, the zero-residual condition is one scalar inequality. Across default sets it is combinatorial because those sets and their capacities can change with D.

Remark 13.23 (Reflexive-cascade elimination).

The settlement discipline of Definition 11.1 removes direct hub-price revaluation of fixed settlement balances. The behavioral assumptions of Theorem 11.2 remove its specified clearing-induced liquidity withdrawal. Position losses, settlements, and encumbrances can still consume drawable resources. Corollary 11.7 gives the resulting capacity deduction. ADL claims retain their dependence on position marks.

13.6 Scope of the adversarial bounds

Table 2 records the adversary model, defence, and bound for each adversarial proposition above, with the classification of the matching construction. Matched means a construction achieves the bound up to the stated constant; one-sided means only the bound is proved.

Table 2. Scope and mathematical status of the adversarial bounds.
Proposition Adversary Defence Bound (payoff, or cost where stated); matching
Prop 13.4 \mathcal{A}_{\mathrm{AM}}(T) Rate-limiter \delta_\Phi g_\Phi\delta_\Phi(1-e^{-\kappa T})/\kappa; exact in the stated first-order model
Prop 13.7 \mathcal{A}_{\mathrm{AM}}(T) AMM fee f_{\mathrm{AMM}} [q_{\max}(\ell_Vg_\Phi\delta_\Phi/\kappa-2f_{\mathrm{AMM}})-c_{\mathrm{gas}}]_+; one-sided, including abstention
Prop 13.9 \mathcal{A}_{\mathrm{AM}}(T) (X,Y,\Delta_{\mathrm{lag}}) gate eq. (72); exact for the auxiliary Gaussian AR(1) screens
Prop 13.12 \mathcal{A}_{\mathrm{RS}} Zero-lag re-margining \min\{d,Q\mathbb{E}X_\tau^-\}-2f_{\mathrm{AMM}}Q; exact Gaussian advantage before fees G(C_{\mathrm{att}})-G(C_{\mathrm{hon}})
Prop 13.14 \mathcal{A}_{\mathrm{CE}} PSD correlation stress set \Delta_\rho(\Pi) - c_{\mathrm{ev}}, eq (74); one-sided
Prop 13.17 \mathcal{A}_{\mathrm{SR}}(K+1) \chi-cap + KYC cost \min\{\mathrm{IF}_0,K\min(\varepsilon C_{\mathrm{per}},\chi\mathrm{IF}_0)\}-(K+1)c_{\mathrm{KYC}}; one-sided without an execution construction
Prop 13.19 \mathcal{A}_{\mathrm{SR}}(K) Collateral + hedge friction eq. (77); exact conditional identity
Prop 13.21 default set D five-stage waterfall \mathcal{C}^{\mathrm{abs}}(D); exact residual, with the Stage-1-only zero-residual boundary attained only as a limit

Remark 13.24 (One-sided bounds are structural).

Three entries are one-sided bounds without matching constructions. Proposition 13.7 assumes a pathwise value-sensitivity cap. Proposition 13.14 does not construct an event that realises the correlation shortfall net of cost. Proposition 13.17 is an accounting bound and does not prove that the required offsetting positions execute at the stated losses. Their unprofitability conditions are calibration results, not matching attacks.

14 Reproducible synthetic comparisons

The comparisons examine loss coverage, detection of a changed loss frequency, and funded execution of a buyback. Their probabilities come from declared generators. A breach is an observation whose loss exceeds margin. Mean shortfall averages the unfunded amount across all held-out observations, including zero-shortfall outcomes.

The study fixes generator seed 120018 and a training cutoff of 1{,}000 observations. Each loss is 100 with its stated Bernoulli probability and zero otherwise. The probability is 0.005 during training and the first 2{,}500 held-out observations. It becomes 0.015 for the remaining 2{,}500 observations. All forecasts are fixed at the training cutoff. The Gaussian baseline estimates mean and variance from training data only. Its exact linear-family premise fails for this digital loss, which makes it a misspecified comparison. The nominal full-loss forecast uses the known training generator and q=0.01, giving ES 50. The stress envelope permits event probability up to 0.02 and gives ES 100. The isolated comparator funds the full 100 contractual loss.

Table 3. Synthetic held-out loss comparison over 5,000 observations. Amounts use one settlement unit.
Forecast Margin Breaches Coverage Mean shortfall
Gaussian linear baseline 14.88 51 98.98% 0.868
Known nominal full-loss ES 50.00 51 98.98% 0.510
Joint stress envelope 100.00 0 100.00% 0.000
Isolated full-loss limit 100.00 0 100.00% 0.000

Training contains three loss events, and the held-out period contains 51. The empirical held-out ES at tail mass 0.01 is 100 for every strategy. The largest unfunded losses are 85.124, 50, 0, and 0 in table order. Margin equals capital use per 100 notional in this experiment. The loss comparison has no trading step, so its execution cost is zero. Coverage here means the fraction of losses no larger than the stated margin. ES does not generally prescribe a margin-exceedance frequency of q. The stress envelope contains both generator regimes, which explains its coverage in this construction.

The health study uses 200 independent null replications and 200 independent shifted replications, each of length 1{,}000. The Bernoulli monitor has p_0=0.005, p_1=0.015, and lifetime error budget 0.05. Seven null runs cross the threshold, an observed rate of 0.035. Under the shifted generator, 172 runs cross, an observed rate of 0.86. Their mean detection delay is 345.047 observations, conditional on detection. Corollary 5.8 gives a terminal-count threshold of 12 and detection probability at least 0.817249. These finite outcomes illustrate the stated null and alternative laws. The probability bound uses the theorem, rather than the observed fraction of alarms.

A separate funded study uses 1{,}000 independent treasury books with initial cash 150 and protected target 100. The declared decision-time generator has favorable, adverse, and failed-fill probabilities 0.94, 0.05, and 0.01. Set r=0.5, X=0.5, pre-action marked value 150, and executable-value budget R_t^{\mathrm{buy}}=0. The all-in purchase budget is 25. The one-step adverse event is a negative realized trade result, with probability budget q=0.06 and Y=0.94. The tested post-action credit requirement stays 80, with target multiplier 1.25 giving target 100. A stress payment of 80 in the primary currency is due after the fill, with no other competing payments. These fixed synthetic states satisfy the prospective credit and liquidity conditions for every permitted fill. Each action is eligible in the stated model. The purchase spends curve input 20 plus fee 0.2 in a pool with reserves R_S=R_M=1{,}000. A successful fill receives 1{,}000/51 hub units and leaves cash 129.8. The entry loss at the initial unit mark is 151/255. A subsequent fee-free sale uses hub reserve 1{,}000 and settlement reserve 1{,}100 or 800. The corresponding net round-trip results are 62/65 and -313/65. A failed fill receives zero units and pays the 0.2 fee. The generator’s expected net result is 17/26>0, so the joint-value condition admits a nonzero purchase. The realized study has eight failed fills and mean net result 0.627308. Its mean all-in debit is 20.04 and mean entry slippage plus fee is 0.589020. Every book retains at least 129.8 cash after the purchase. These probabilities are specified before selection, and each book uses no future observation in its gate.

The reproducibility files include the generator inputs, forecast cutoff, raw loss and fill records, and formula-table inputs. The executable study regenerates Table 3 and the numerical ratios in Table 4. The remaining tables state policy rules and theorem bounds. Exact rational checks cover funded waterfall transitions, deadline sequencing, and the stated adverse examples. These files accompany the paper in supplements/ccp-risk-supplement.zip. The archive also contains the finite completion calculation, persistent monitoring, and single-asset durable reference, with dependency specifications and historical execution records. Its SHA-256 digest is e59bcf86c06c8399eb3cafc6ea1a996ab96d00b586f9225efe2c125a42ffcb9b. Synthetic probabilities and costs are declared inputs. Venue-specific use requires observed loss, fill, liquidity, legal-event, and execution-cost data for the chosen horizon and selection rule.

15 Open Problems

Open Problem 1 (Diversification bounds).

Derive the optimal issuer-concentration cap \omega_{\max} and non-stablecoin floor \omega_{\min} for the insurance fund. Minimise the joint-tail bound of Theorem 12.4 subject to a capital-efficiency constraint, and characterise the Pareto frontier in (\omega_{\max},\omega_{\min}).

The sequencing problem has an exact solution for a finite action catalogue and scenario tree. The proposition states that baseline before the open problem asks for scalable policies with interacting pools and payment deadlines.

Proposition 15.1 (Finite funded liquidation scheduling).

Fix a finite action set, finite scenario tree, and horizon T. The state records pool reserves, remaining inventory, funded cash, obligations and their deadlines, and current legal eligibility. An admitted sale consumes owned inventory and adds only its actual net curve proceeds to cash. A payment debits at most available cash and leaves any unpaid obligation recorded. For execution cost c_t and terminal shortfall cost J_T, backward induction gives J_t(s)=\min_{a\in\mathcal A_t(s)} \left\{c_t(s,a)+\sum_\omega p_t(\omega\mid s,a)J_{t+1}(T_t(s,a,\omega))\right\}. Include a recorded no-sale or suspended outcome when the current action set has no executable sale. This recursion computes an optimal policy for the stated finite model while preserving funded cash and inventory.

Proof. The finite scenario tree has finitely many reachable histories. At its leaves the terminal cost is specified. At each earlier node, evaluating every admitted action and its finite successor costs gives the minimum by backward induction. Every transition preserves cash and inventory by its admission conditions. Outstanding obligations persist independently of the optimization cost. ◻

Open Problem 2 (Liquidation sequencing with funding and deadlines).

Under fixed independent invariant paths, fixed fees, and fixed total sales, cumulative proceeds are independent of ordering. Proposition 15.1 makes sequencing substantive through funding availability, deadlines, coupled reserves, and observed changes. For example, sales into two constant-product pools can produce 6 and 4 currency units, with zero initial cash and a 5 payment due after the first sale. Selling the first pool before the second meets the deadline and leaves 5 cash after both sales. The reverse order leaves a 1 unpaid obligation at the deadline. Both use the same cumulative inventory and proceeds. Develop scalable policies for the coupled case, with approximation bounds against the exact finite recursion and the same funded transition rules.

Open Problem 3 (Optimal shrinkage intensity).

The blending weight w_s in Remark 3.11 is exogenous. Derive the Ledoit-Wolf-type optimal w_s^* for structural priors with known sparsity pattern (a graph Laplacian), extending [9] to the graph-structured-prior case.

Open Problem 4 (Closed-form haircut optimisation under copula).

Given a copula \mathsf{C} on joint stablecoin depegs, derive the optimal haircut schedule \{h_k^*\} minimising the expected copula-tail loss of Theorem 12.4 subject to a total-haircut budget constraint. For Gaussian, Clayton, and Gumbel copulas, characterise when \{h_k^*\} is unique and when ties occur.

Open Problem 5 (The regularised system at the impasse surface).

Replace the instantaneous withdrawal law (49) by a first-order relaxation of the withdrawal rate with time constant \epsilon > 0. The constrained system (52) is the \epsilon \to 0 limit, in the sense in which Takens [24] obtains constrained equations from slow-fast systems, and the withdrawal-rate coordinate of the critical manifold is unbounded as \Sigma is approached, so the limit is not the fold-canard setting of Krupa-Szmolyan [57] and Benoît et al. [20, 21]. Characterise the \epsilon \to 0 limit of the regularised trajectories that reach \Sigma from the subcritical side, their scaling in the distance to \mathcal{E}, and whether a blow-up after compactification of the withdrawal-rate coordinate recovers the selection hypothesis of Remark 9.5, which the lag regularisation of that remark does not.

Open Problem 6 (Endogenous settlement-asset contagion).

Theorem 11.2 assumes the settlement asset’s price is exogenous to L. When the clearing system grows sufficiently large that its settlement flow affects the settlement asset’s own stability, the exogeneity assumption fails. Derive the scaling condition under which this feedback becomes non-negligible, and characterise the induced second-order reflexive channel.

Open Problem 7 (Sharp bound on cascade depth).

Corollary 6.21 bounds cumulative absorption and gives at most K rounds with a nonempty default set. A sharp expected-depth bound under specified joint buffer assumptions remains open. Fix a joint law for the per-counterparty margin buffers above maintenance, with marginal density \phi(C^{\mathrm{buf}}) and stated dependence. Derive a sharp bound on the expected cascade depth \mathbb{E}[N_{\mathrm{rds}}] as a function of \phi, that dependence, the socialisation cap \kappa, and the concurrent-default size |D|.

Open Problem 8 (Tight adversarial lag-window tail).

Proposition 11.19 bounds the linear autocorrelation at lag \Delta_{\mathrm{lag}}; Remark 11.20 gives the Chebyshev bound on the lag-window average under finite variance and an exponential bound, with exponent linear in the window length, under sub-Gaussian innovations. Identify the weakest condition on the innovations and on the estimator under which the gate-bypass probability has a sharp exponential tail, and construct an adversarial innovation sequence saturating the Chebyshev bound when no moment beyond the second is available.

Open Problem 9 (LP concentration versus fee-revenue scale).

Proposition 9.11(iii) shows that in a levered clearing layer with \Gamma f(L) > P_M a withdrawal in its stated positive-price crossing range carries the state across \Sigma. Fee-revenue scale encourages LP concentration [53, 54]. Jointly optimise the fee schedule, the per-LP withdrawal-rate limit, and the strict concentration cap s_{\max} < s^* to maximise pool-level welfare subject to every single-LP withdrawal leaving the state strictly subcritical.

Open Problem 10 (Heavy-tailed ES aggregation).

Corollary 3.25 resolves common-family linear Student-t aggregation for \nu>2. Determine useful diversification bounds for heterogeneous marginal tails, non-elliptical dependence, and nonlinear instrument losses. Specify their joint loss laws and compare exact scenario ES with the certified approximation in Proposition 3.3. Characterise when a uniform remainder bound retains material capital efficiency.

Open Problem 11 (Porting versus liquidation frontier).

Proposition 6.17 computes a feasible full port’s waterfall benefit from two resource-consistent routes. Characterise the optimal partial-port allocation using the same valuation, occurrence, liability, and funding perimeter in Definition 6.16. Include every member-level constraint (38), settlement deadline, default-set size, hub-asset concentration, and pool-depth dynamic. The objective uses the full route difference, with the clipped special case (39). Relate the allocation rule to the EMIR Art. 48 porting framework [49].

Open Problem 12 (Dynamic correlation margin under event calendars).

Proposition 13.14 bounds the synthetic-directional attack under a static positive-semidefinite stress set of correlation matrices. Develop an event-aware dynamic correlation model in which the margin system’s stress set updates against a scheduled event calendar, and prove a tighter attack bound under the event-conditional measure.

A Numerical calibrations for cross-margin efficiency

Equation (15) expresses m^{\mathrm{cross}}/m^{\mathrm{iso}} as a closed form in (N_{\mathrm{br}},\bar\rho_{\mathrm{eff}},D^{sp},D^{pE}) for the certified centered linear, balanced same-direction submodel. The following table uses the rates in Definition 3.13.

Those rates are (\mu^s,\mu^p,\mu^E)=(0.10,0.05,1.0).

With D^{sp}+D^{pE} per unit notional, m^{\mathrm{iso}}_{\mathrm{per\,spoke}}=1.15\mathcal N. In the first three rows the within-spoke hedge factor is 1.07/1.15\approx0.930 and the remaining factor is \sqrt{\bar\rho_{\mathrm{eff}}+(1-\bar\rho_{\mathrm{eff}})/N_{\mathrm{br}}}, equal to 0.529, 0.678, and 0.742 at \bar\rho_{\mathrm{eff}}=0.20, 0.40, and 0.50; the fourth row has hedge factor 1.11/1.15\approx0.965 at \bar\rho_{\mathrm{eff}}=0.40. An upward scalar stress is valid in this table because every post-hedge component has the same sign. It is not the stress rule for a signed book.

Table 4. Representative values of the ratio (15) at equal per-spoke notionals and a non-binding floor.
Scenario Inputs m^{\mathrm{cross}}/m^{\mathrm{iso}}
Balanced portfolio, base scenario N_{\mathrm{br}}=10, \bar\rho_{\mathrm{eff}}=0.20, D^{sp}+D^{pE}=0.08 \approx0.49
Balanced portfolio, stress scenario N_{\mathrm{br}}=10, \bar\rho_{\mathrm{eff}}=0.40, D^{sp}+D^{pE}=0.08 \approx0.63
Balanced portfolio, tighter stress N_{\mathrm{br}}=10, \bar\rho_{\mathrm{eff}}=0.50, D^{sp}+D^{pE}=0.08 \approx0.69
Concentrated hedge N_{\mathrm{br}}=10, \bar\rho_{\mathrm{eff}}=0.40, D^{sp}+D^{pE}=0.04 \approx0.65

B Margin-breach response and cross-pool unwind

A margin-breach event occurs when a position’s realised loss exceeds its available collateral, whether because the parametric ES estimator understated the tail (correlation-model breakdown, whether detected by the health predicate \mathcal{H} or still undetected), because a tier transition drained correlation credits to below the new-tier floor, or because an execution slippage exceeded the scenario catalogue. The response protocol must propagate the breach through the waterfall of §6.2 and, under compliance-tier interaction, respect tier-boundary isolation.

For a position spanning several tiers, the governing booking and allocation records identify the liability assigned to each book. The primary leg is the designated leg whose booked liability initiates the breach under that allocation rule. Tier-preserving channels are the permitted loss transfers within the corresponding book’s liability and resource perimeter. The protocol requires this allocation input. Hedge direction alone does not determine it.

Definition B.1 (Margin-breach response protocol).

On detection of a margin breach on position \Pi at time t:

(1)

Freeze. New-position opening on \Pi’s leg is halted and the health predicate \mathcal{H} is set to false for the affected leg.

(2)

Retain and increase requirements. Existing positions follow the degraded recurrence (27). The preceding requirement persists until the recorded recovery decision.

(3)

Default handling. Realised loss beyond available collateral enters the waterfall of §6.2, after senior commitments. An increased requirement creates a margin call until funded. Collection, seizure, and liquidation follow the current eligibility predicate of Definition 7.4. The ledger separates funded collateral, outstanding trading loss, and reassessment receivables.

(4)

Tier-isolated unwind. If \Pi spans multiple tiers (e.g., a Warm-tier leg and a Hot-tier leg of a synthetic position), the breach is first allocated to the tier of the primary leg, then propagates only through tier-preserving channels. Hot-tier gained correlation credits that the position relied on are drained before any Warm-pool socialisation.

(5)
Insurance-fund selection. Default allocations to the insurance fund draw from the \mathrm{IF} corresponding to the position’s tier at breach-detection time; Warm-tier breaches draw from \mathrm{IF}^{\mathrm{gated}}, Hot-tier breaches from the main \mathrm{IF}.

Proposition B.2 (Single-position-breach containment).

Let account i be the only account contributing gross loss at time t. Write R:=(L_i-C_i)_+,\quad A:=E_{\mathrm{SIG}}+\mathrm{IF}^{\mathrm{tier}},\quad S:=\sum_{j\in\mathcal{B}}a_j,\quad U:=\sum_{j\in\mathcal{P}}\pi_j. Set \pi_k=0 outside \mathcal{P}. For another account k, define allocated loss by \Delta_k^{\mathrm{prop}}:=\ell_k+\delta_k. Then \Delta_k^{\mathrm{prop}} \le a_k\mathbf1_{\{R>A\}}+\pi_k\mathbf1_{\{R>A+S\}}. \tag{79} More precisely, for U>0, \delta_k=\frac{\pi_k}{U}\min\{(R-A-S)_+,U\}. For U=0, every \delta_k=0. The aggregate allocated loss and the remaining obligation satisfy \begin{gather*} \sum_{k\ne i}\Delta_k^{\mathrm{prop}}=\min\{(R-A)_+,S+U\},\\ R=e+d+\sum_k\ell_k+\sum_k\delta_k+\Delta^{\mathrm{res}}. \end{gather*} The terminal residual remains unpaid. A subsequent allocation of unpaid claims u_k adds u_k to that account’s total loss. A member’s loss is the sum over its accounts.

Proof. Stage 4 draws at most a_k and starts only when R>A. Stage 5 starts only when R>A+S. Its proportional allocation gives the displayed ADL term. Adding the cash debit and extinguished claim proves (79). Summing the two stages gives the aggregate identity. The waterfall residual gives the final accounting identity. ◻

Proposition B.3 (Tier-separated loss-absorption identity).

Let j\in\{\mathrm{Hot},\mathrm{Warm}\}. Suppose the Hot and Warm books have segregated collateral, profit claims, skin-in-the-game tranches E_{\mathrm{SIG}}^j, and insurance funds \mathrm{IF}^j, with \mathrm{IF}^{\mathrm{Warm}}:=\mathrm{IF}^{\mathrm{gated}}. Each book applies Definition 6.8 independently, with funded caps a_k^j from its own collateral, seizures, and encumbrances. At time t, let D_t^j be the defaulting accounts in book j, let \mathcal{B}_t^j:=\{k\notin D_t^j:w_k>0\} be its socialisation base, and let \mathcal{P}_t^j be its profitable accounts. Define the post-collateral loss, the prefunded drawable resources, the ADL-eligible claims, and their combined loss-absorption limit by \begin{align*} R_t^j&:=\sum_{k\in D_t^j}(L_k-C_k)_+, \tag{80} \\ A_{\mathrm{pref},t}^j&:=E_{\mathrm{SIG}}^j+\mathrm{IF}^j+\sum_{k\in\mathcal{B}_t^j}a_k^j, \tag{81} \\ A_{\mathrm{ADL},t}^j&:=\sum_{k\in\mathcal{P}_t^j}\pi_k, \qquad A_{\mathrm{abs},t}^j:=A_{\mathrm{pref},t}^j+A_{\mathrm{ADL},t}^j. \tag{82} \end{align*} The SIG tranche is CCP equity. The insurance fund and capped socialisation are mutualised member resources. The ADL term consists of profit claims and is not prefunded or mutualised. Then the tier-j residual is exactly \Delta_{t,j}^{\mathrm{res}}=(R_t^j-A_{\mathrm{abs},t}^j)_+. \tag{83} Hence book j clears without residual if and only if R_t^j\leq A_{\mathrm{abs},t}^j. Neither its draws nor its residual enter the other book. Cold-tier instruments admit no new cleared position under Definition 7.1; this proposition therefore makes no Cold-tier loss-absorption claim.

Proof. Apply the residual formula of Theorem 6.12 separately to each segregated book. The tier-selection rule in Definition B.1(5) and the segregation assumption exclude cross-book fund draws, socialisation, and ADL. ◻

Remark B.4 (Cross-pool unwind on Hot \to Warm downgrade).

A Hot \to Warm downgrade recalculates main-book correlation credits and the complete gated-pool requirement. When both actions remain eligible, the system prepares a main-book close and gated-pool opening. It validates current positions, funded balances, margin requirements, and the legal-event generation before committing both local changes atomically. Equation (27) retains the preceding requirement during degraded operation. A new legal event requires recomputation of the eligible transition. When one action becomes ineligible, the applicable rule determines the permitted funding, closure, or transfer action. The local atomicity claim concerns committed local state. Observation delay, external execution, and external settlement finality follow the recorded provider rules.

C Capital for funded completion

A settlement plan commits its resources across several payment dates. Information between those dates changes both the remaining obligation and the funding available to discharge it. Definition 6.6 requires one policy that meets every represented deadline. We now characterize that policy’s exact cash requirement on a finite observable state graph. The state carries unpaid obligations, consumed facilities, and the authority required for each remaining action. This makes funding after an observation part of the calculation.

C.1 Conditional risk and cash at a deadline

Expected Shortfall describes a loss distribution under a specified information set. Repeated decisions require the information structure as well. Recursive risk functionals and their time-consistency properties are established subjects [70]. Here their role is to specify a conditional loss budget alongside the cash needed for completion.

Example C.1 (A four-leaf loss distribution).

Let four terminal outcomes have equal probabilities and losses 0,0,0,100. The first observation distinguishes the first pair from the second pair. The second observation identifies the outcome within that pair. Write \mathop{\mathrm{ES}}_q for the average of the worst probability mass q. At q=1/2, the initial static value is \mathop{\mathrm{ES}}_{1/2}(0,0,0,100)=50. The conditional values after the first observation are 0 and 100. Applying the same functional to these values gives \mathop{\mathrm{ES}}_{1/2}\bigl(\mathop{\mathrm{ES}}_{1/2}(0,0),\mathop{\mathrm{ES}}_{1/2}(0,100)\bigr)=100. With cash as the sole resource, a plan funded by 50 cannot meet the last obligation in the second branch.

For a fixed plan on a finite probability tree, let \ell(s,z) be the economic loss between adjacent observations. A nested conditional risk value has the form \rho(s)=\mathop{\mathrm{ES}}_{q(s)}\!\left(\ell(s,z)+\rho(z)\mid s\right), \qquad \rho(t)=L(t) \quad\hbox{at a terminal state }t. The conditional probabilities, tail mass q(s), and terminal loss L(t) belong to the specified risk model. A policy can restrict the permitted actions through a recorded budget for these values. Its funding test still accounts for the actual order of receipts and payments. A payment of 100 followed by a receipt of 100 has zero net loss and requires 100 at the earlier deadline.

For a controlled plan, the current state carries a risk budget r(s)\ge0. Each action assigns budgets to its successor states before their outcomes become known. Those budgets accompany the resulting obligations and funding commitments.

An adapted policy chooses each action using only information already observed. Its successor budgets must therefore be assigned before the next outcome is known.

Proposition C.2 (Conditional budgets through a plan).

Fix a finite observation tree and the conditional loss law of each permitted action. Suppose every terminal state satisfies L(t)\le r(t). For each action a permitted at s, require \mathop{\mathrm{ES}}_{q(s,a)}\!\left(\ell(s,a,z)+r(z)\mid s,a\right)\le r(s). Then every adapted policy using these actions has nested conditional risk at most r(s) from each state s.

Proof. At a terminal state, the hypothesis bounds the remaining loss. Suppose the result holds at every successor of s. For the action selected at s, each successor’s nested risk is at most its assigned budget. Monotonicity of Expected Shortfall bounds the current nested risk by the displayed quantity, hence by r(s). Backward induction completes the proof. ◻

The conditional law in this proposition includes the information used to select the action. An older-information estimate requires a corresponding current conditional certificate before it supplies that law. The budgets constrain future risk choices and supply no cash by themselves.

C.2 Observable states and conserved funding

All cash amounts below use one stable settlement unit. One node represents a history available to the decision maker. Its noncash state records every liability, resource limit, encumbrance, provider condition, and authority condition used by the remaining plan. Unobserved distinctions remain possible outcomes of a common decision. Two histories can share a node when their recorded states permit exactly the same remaining continuations.

Definition C.3 (Finite completion model).

Fix a finite acyclic state graph with a finite action set A(s) at each nonterminal state s. Each action has a nonempty finite set Z(s,a) of possible successor states. The action is selected before its successor becomes known. From cash b, action a first pays d(s,a)\ge0 and retains at least h(s,a)\ge0. The next observation identifies z\in Z(s,a) and settles the signed cash increment g(s,a,z). The resulting cash is b'=b-d(s,a)+g(s,a,z). All intermediate deadlines and payment-order constraints have their own nodes. At a terminal state t, payment m(t)\ge0 discharges every remaining represented obligation. The action sets, increments, and successor sets depend on recorded state, with cash entering only through these requirements. Retaining additional cash preserves the same permitted continuations.

The increment g contains delivered receipts less payments at its checkpoint. When receipts fund those payments, the model records their availability before the debit. Any earlier debit requires an earlier checkpoint. An immediate draw therefore precedes the payment it funds through a separate draw node. An enforceable obligation to supply funds and the cash supplied under that obligation remain distinct state entries.

A draw consumes the facility’s remaining limit and creates its repayment liability. Its child state retains that liability until an exact repayment discharges it. Terminal cash m includes every residual repayment, fee, and completion obligation represented by the plan. Each physical receipt contributes once along an executed history. Mutually exclusive histories can use the same undrawn facility, within its stated limit on each history. Concurrent plans sharing that limit require a joint state and one aggregate resource reservation.

Provider failure belongs to the successor set wherever the stress contract requires it. An action that cancels, closes, or transfers a position retains the resulting settlement and recovery obligations. Its action set records the authority and terms that permit that change. These are premises of the finite model. The cash calculation determines what follows from them.

C.3 The exact continuation requirement

The calculation works backward from final payments. Each action needs cash for its immediate debit, its retained floor, and every continuation still possible afterward. The least demanding permitted action determines the current requirement.

For a terminal state, set K(t)=m(t). Define the threshold for action a and the minimum completion cash by backward recursion: \begin{align*} T(s,a)&=d(s,a)+\max\left\{ h(s,a),\max_{z\in Z(s,a)}\bigl[K(z)-g(s,a,z)\bigr]\right\}, \tag{84} \\ K(s)&=\min_{a\in A(s)}T(s,a). \tag{85} \end{align*} The minimum of an empty action set is +\infty. All other input amounts are finite. The value +\infty identifies a state from which finite cash cannot complete the permitted plan.

Theorem C.4 (Exact adapted completion cash).

Under Definition C.3, fix a state s and finite cash b\ge0. An adapted permitted policy meets every represented deadline and terminal obligation exactly when b\ge K(s). Every action satisfying T(s,a)\le b admits such a continuation.

Proof. Induct on the maximum remaining path length. At a terminal state, the payment is feasible exactly when b\ge m(s). Suppose a feasible policy chooses a at a nonterminal state. The current payment and retained floor imply b\ge d(s,a)+h(s,a). For each possible successor z, the induction hypothesis requires b-d(s,a)+g(s,a,z)\ge K(z). Taking the maximum gives b\ge T(s,a)\ge K(s).

Conversely, suppose finite b\ge K(s). Finiteness of the action set supplies an action attaining the minimum. Its threshold is at most b, so its payment leaves the required floor. Every successor receives cash at least K(z). The induction hypothesis supplies a completing policy after that successor is observed. Their composition uses only the current observed history and cash. The same argument applies to any action whose threshold is at most b. ◻

Corollary C.5 (Funding retained through execution).

Start from b_0\ge K(s_0) and choose only actions with T(s,a)\le b. Then every represented execution retains b\ge K(s) at each decision. When K(s)<+\infty, an immediate cash distribution can release at most b-K(s) while preserving this condition. The distribution must itself preserve the recorded state and satisfy its governing authority and encumbrance rules.

Proof. Equation (84) implies b-d(s,a)+g(s,a,z)\ge K(z) for each successor. Induction preserves the inequality until terminal discharge. After a state-preserving distribution w, the theorem applies exactly when b-w\ge K(s). ◻

The outer minimum precedes the maximum over successors because one action must cover every outcome still possible when it is chosen. Interchanging them permits knowledge of a future observation. For example, two actions may each avoid a 100 payment in one outcome and leave it in the other. If either outcome can follow either action, the requirement is 100. Selecting the favorable action after seeing the outcome incorrectly gives zero.

The recursion uses all represented branches, including branches with small positive probability. Replacing its maximum by Expected Shortfall changes the guarantee to a risk-budget statement. The local floor h can include any cash reservation required by the chosen risk policy. A restriction that persists after the next observation remains in the successor state. Cash reserved for one legal claimant becomes available to another only through a permitted transfer.

C.4 Completion with funding after an observation

Example C.6 (A draw with a funded repayment).

Assume a facility supplies 60 before a payment of 100. Its repayment is 65, due after a separate receipt of 65. The facility permits one draw. Its remaining limit becomes zero when that draw settles. The terminal repayment requires K=65. At the payment node, the requirement is \max\{100,100-65+65\}=100. At the preceding draw node, it is \max\{0,100-60\}=40. Initial cash 40 therefore funds the payment and the repayment on this specified path. The balances are 40, 100 after the draw, zero after payment, and 65 after receipt. Repayment leaves zero.

Removing the later receipt while retaining the repayment raises the draw-route requirement to 105. If a cash-only route exists, its requirement is 100 and the minimum selects that route. Adding a facility-failure branch also raises the root requirement to 100, because that branch still owes the payment. A timely independent backup can reduce this amount according to its own cost, capacity, and repayment terms.

For a conditional plan, the first observation can select between a low-payment state and the funded state of Example C.6. If the low-payment state needs 20, the root requires 40. Only the observed high-payment branch draws the facility. This is an adapted strategy with initial cash below the largest payment. It uses named, timed resources and retains every associated liability.

C.5 Durable completion and retained margin

The graph calculation specifies required cash at decision states. A workflow is one admitted settlement plan with its own payment identities and reserved resources. Its durable record connects graph states to payments and receipts that may arrive later or be reported repeatedly.

The cash recursion supplies an execution rule when observations and payments have distinct arrival times. Between two graph states, cash may await a payment, a dispatched payment may remain uncertain, and an earlier payment may return. The settlement record must retain each of these states.

Example C.7 (Completion with a separate margin).

Add a retained margin of 30 to Example C.6. Initial cash 70 becomes 130 after the physical draw, 30 after payment, and 95 after the later receipt. Repayment leaves 30, which remains reserved after the obligations are discharged. A separately admitted healthy repricing to zero margin releases this 30. If 20 of the earlier payment then returns, the payment obligation reopens by 20. The returned cash funds a new payment of 20. The pool can already have assigned the released 30 to another workflow.

Fix a permitted policy \pi, which selects one action at every reachable state. Let K_\pi be the recursion (85) on the graph restricted to those actions. Let M\ge0 be an independently retained cash margin, unavailable for the plan’s payments. The floors h in Definition C.3 still apply to the remaining cash.

Proposition C.8 (Completion cash with an independent reserve).

Suppose M is constant throughout the selected policy, including terminal discharge. Then the exact total cash requirement is K_\pi(s)+M.

Proof. Write x=b-M for spendable cash. The payment and observation rule gives x'=x-d(s,\pi(s))+g(s,\pi(s),z). The retained floor applies to x, and the terminal payment requires x\ge m(t). Theorem C.4 applied to the restricted graph therefore gives x\ge K_\pi(s). Adding M proves the claim. ◻

This decomposition assigns separate functions to M and the cash in the completion problem. A margin already included in the floors or terminal requirements must not be added again. Changing M requires a new current funding check. An increase can produce a shortfall even when the initial admission met the proposition’s bound.

A physical occurrence is one actual provider-reported transfer, distinguished from repeated reports of that transfer. A settlement projection calculates the workflow’s cash from these occurrences and its recorded releases. Holds reserve current cash internally, while external reservations protect commands already prepared for payment.

Definition C.9 (Settlement projection).

A workflow binds an immutable graph, policy, payment identities, payees, and permitted action modes. Its cash projection is C_f=b_f^0+F_f+R_f-P_f-W_f, where b_f^0 is assigned initial cash, F_f is physical funding, R_f is returned cash, P_f is gross physical payment, and W_f is released cash. Each sum uses distinct physical occurrences in one asset and settlement unit. An occurrence identity specifies the provider, account, asset, unit, namespace, epoch, and provider reference. Funding and payment-return records use the same occurrence identity space.

An internal hold reserves cash for a workflow without creating a payable obligation or an external command. External reservations cover prepared payment commands. If these quantities are H_f and E_f, respectively, aggregate availability subtracts \sum_f(H_f+E_f) and unmatched returns from actual pool cash. Facility reservations constrain future draws and supply cash only when a physical credit arrives.

The durable reference uses one settlement authority and one serializable transaction for the workflow state, holds, commands, and settlement journal. A provider execution lies outside that database transaction. At an ordinary pending stage, its hold covers \max\{0,C_f-E_f\} whenever current funding and authority permit that reservation. A failed reservation records a shortfall while preserving the admitted physical facts. Preparing or dispatching another payment requires cash for its external reservations and the current retained margin. The checks also require the workflow’s graph binding to remain current and its resource reservations to remain funded.

Serializable transactions make concurrent recorded updates equivalent to a sequential order. Durable storage preserves committed updates across restart. Integral settlement quanta express amounts as whole multiples of the smallest permitted settlement unit. The following correspondence relates such committed records to the cash recursion, conditional on the stated external funding and observation facts.

Proposition C.10 (Correspondence at committed checkpoints).

Consider the reference transition rules under Definition C.9, with one controlled durable store and integral settlement quanta. Fix a validated finite graph, its policy \pi, and constant separate margin M. Assume truthful admitted occurrence identities, amounts and outcomes, current permissions, and the resource capacities used by the selected policy. Assume the recorded graph remains current for execution and the store preserves committed transactions across restart. Between compared graph checkpoints, require the represented receipts and payments, with any returned payment restored before further graph progress. Then each successful graph advance follows the selected edge and retains C_f-M\ge K_\pi(s) at its next decision state. Replaying an admitted physical occurrence does not increase the cash projection. At a completed checkpoint, every payment obligation incurred along the recorded history is discharged in the admitted settlement state.

Proof. Admission checks C_f\ge K_\pi(s_0)+M and reserves both current cash and the selected policy’s future resource use. Before a stage begins, the same cash inequality is checked at its current state. The outcome transition waits for the stage’s payments to discharge their obligations. It binds the observation to the workflow, graph, action and preceding history. Funding consumes the corresponding resource reservation only with its bound physical credit. Reconciliation waits for all edge receipts and payments, and for any earlier reopened obligation to be discharged. The cash identity then gives exactly C_f'=C_f-d+g across the represented step. The successor check requires C_f'\ge K_\pi(s')+M before advancing the graph state.

A repeated identical occurrence has no further cash effect. A conflicting reuse remains a conflict and supplies no second credit. The terminal transition creates the remaining debt payments and completes only when their current outstanding amounts vanish. Its completed-payment record retains the earlier obligations for subsequent return checks. All changes within each transition commit in the same transaction, so restart preserves either its predecessor or its committed successor. Induction over committed graph advances proves the assertion. ◻

Completion is evaluated using the settlement events admitted so far. A later return preserves the earlier completion receipt as history and places the reopened obligation in recovery. The next payment uses the current unpaid amount after existing reservations. Recovery retains the workflow’s next graph state and its separate obligations. The subtraction of W_f prevents an earlier release from becoming available to that workflow again.

The margin rule retains the preceding requirement during degraded operation, as in Proposition 5.17. A healthy signal alone leaves an existing degraded state in force. A recorded recovery decision can clear that state, and admitted healthy repricing can reduce the margin. Once obligations are discharged and the current margin is zero, the remaining internal hold can be released. These decisions remain inputs from the governing authority.

The correspondence concerns a single authority’s admitted records and transitions. It assumes truthful external facts, available resources, valid permissions, and storage that resists rollback by its operator. Graph stages order the represented deadlines, while real settlement timing requires a corresponding provider contract. An unmodeled outcome or incomplete provider payment leaves completion pending. The integral single-asset implementation and its synthetic provider establish this bounded execution path. Empirical loss laws, calibration, legal facility terms, custody, and live provider performance remain separate evidence requirements.

C.6 Finite reference calculation and scope

The reference calculation uses exact rational cash and a finite deadline order. It validates unique cash occurrences, gross resource limits on each history, retained loan liabilities, exact repayments, and repayment deadlines. Every terminal debt enters the discharge amount. Its conditional-budget profile also checks each action’s conditional probabilities, stage loss, successor budgets, and terminal loss. The budget and cash tests use the same successor states. Mutually exclusive draws share a facility limit, while repeated draws along one history consume that limit cumulatively. An edge credits its receipts before debiting its listed payments at the target checkpoint. The model separates another timing order into further nodes.

Backward cash evaluation takes one pass over the validated action edges. The conditional risk checks sort each action’s finite loss distribution to integrate its exact tail mass. The reference ledger validation enumerates represented histories, which can grow exponentially with the horizon. It uses amounts directly and does not enumerate monetary units. A larger implementation can merge histories when it preserves the complete debt, resource, authority, and observation state.

The finite calculation certifies the supplied graph. Its deployment inputs require current evidence for available cash, draw authority, provider survival, receipt timing, and the complete obligation perimeter. Multiple currencies require separate balances and explicit conversion actions under Definition 6.6. Partial observations require information states that retain every compatible continuation. These extensions preserve the question answered by the theorem: which permitted actions still admit funded completion after every represented observation?

References

[1] L. Eisenberg and T. H. Noe. Systemic risk in financial systems. Management Science, 47(2):236-249, 2001.

[2] L. C. G. Rogers and L. A. M. Veraart. Failure and rescue in an interbank network. Management Science, 59(4):882-898, 2013.

[3] R. Cifuentes, G. Ferrucci, and H. S. Shin. Liquidity risk and contagion. Journal of the European Economic Association, 3(2-3):556-566, 2005.

[4] R. Cont and L. Wagalath. Fire sales forensics: Measuring endogenous risk. Mathematical Finance, 26(4):835-866, 2016.

[5] V. V. Acharya and A. Bisin. Counterparty risk externality: Centralized versus over-the-counter markets. Journal of Economic Theory, 149:153-182, 2013.

[6] C. Pirrong. The economics of central clearing: Theory and practice. ISDA Discussion Papers Series, 2011.

[7] Chicago Mercantile Exchange. SPAN: Standard portfolio analysis of risk. Technical documentation, CME Group, 1988 (updated continuously).

[8] P. Jorion. Value at Risk: The New Benchmark for Managing Financial Risk. McGraw-Hill, 3rd edition, 2006.

[9] O. Ledoit and M. Wolf. A well-conditioned estimator for large-dimensional covariance matrices. Journal of Multivariate Analysis, 88(2):365-411, 2004.

[10] P. Embrechts, A. McNeil, and D. Straumann. Correlation and dependence in risk management: Properties and pitfalls. In Risk Management: Value at Risk and Beyond, pages 176-223. Cambridge University Press, 2002.

[11] H. Joe. Dependence Modeling with Copulas. Monographs on Statistics and Applied Probability 134, CRC Press, 2014.

[12] H. Adams, N. Zinsmeister, M. Salem, R. Keefer, and D. Robinson. Uniswap v3 core. Technical report, Uniswap Labs, 2021.

[13] G. Angeris, H.-T. Kao, R. Chiang, C. Noyes, and T. Chitra. An analysis of Uniswap markets. Cryptoeconomic Systems, 1(1), 2021.

[14] H. Uhlig. A Luna-tic stablecoin crash. NBER Working Paper 30256, 2022.

[15] A. Briola, D. Vidal-Tomás, Y. Wang, and T. Aste. Anatomy of a stablecoin’s failure: The Terra-Luna case. Finance Research Letters, 51:103358, 2023.

[16] R. Clements. Built to fail: The inherent fragility of algorithmic stablecoins. Wake Forest Law Review Online, 11:131-154, 2022.

[17] Chainalysis. The collapse of TerraUSD: A forensic reconstruction. Chainalysis Crypto Crime Report, 2022.

[18] N. Fenichel. Geometric singular perturbation theory for ordinary differential equations. Journal of Differential Equations, 31(1):53-98, 1979.

[19] C. K. R. T. Jones. Geometric singular perturbation theory. In Dynamical Systems (Montecatini Terme, 1994), Lecture Notes in Mathematics 1609, Springer, pages 44-118, 1995.

[20] E. Benoît, J.-L. Callot, F. Diener, and M. Diener. Chasse au canard. Collectanea Mathematica, 32(1-2):37-119, 1981.

[21] E. F. Mishchenko, Y. S. Kolesov, A. Y. Kolesov, and N. K. Rozov. Asymptotic Methods in Singularly Perturbed Systems. Monographs in Contemporary Mathematics, Consultants Bureau, 1994.

[22] Y. A. Kuznetsov. Elements of Applied Bifurcation Theory. Applied Mathematical Sciences 112, Springer, 3rd edition, 2004.

[23] L. Perko. Differential Equations and Dynamical Systems. Texts in Applied Mathematics 7, Springer, 3rd edition, 2001.

[24] F. Takens. Constrained equations: A study of implicit differential equations and their discontinuous solutions. In Structural Stability, the Theory of Catastrophes, and Applications in the Sciences, Lecture Notes in Mathematics 525, Springer, pages 143-234, 1976.

[25] R. Riaza. Differential-Algebraic Systems: Analytical Aspects and Circuit Applications. World Scientific, 2008.

[26] V. Venkatasubramanian, H. Schättler, and J. Zaborszky. Local bifurcations and feasibility regions in differential-algebraic systems. IEEE Transactions on Automatic Control, 40(12):1992-2013, 1995.

[27] M. K. Brunnermeier and L. H. Pedersen. Market liquidity and funding liquidity. Review of Financial Studies, 22(6):2201-2238, 2009.

[28] A. Capponi and J.-W. Chang. Settlement speed and financial stability. Finance and Economics Discussion Series 2025-101, Board of Governors of the Federal Reserve System, November 2025. Federal Reserve paper.

[29] D. Bullmann. Keeping settlement risk high on the public policy agenda. The Eurofi Magazine, 30 September 2025. CLS source page.

[30] CLS and FNA. Reimagining same-day FX: Exploring the case for additional settlement cycles. ShapingFX report, 6 March 2025. CLS report page.

[31] The Clearing House. CHIPS. Payment-system description and 2025 liquidity-efficiency data, accessed September 2026. CHIPS source page.

[32] The Clearing House. CHIPS annual statistics. 2025 payment-value table, accessed September 2026. CHIPS annual statistics.

[33] Depository Trust and Clearing Corporation. 2025 Annual Report. 2026. DTCC annual report.

[34] Federal Reserve Banks. Operating Circular 6: Funds transfers through the Fedwire Funds Service. Effective 5 January 2026. Operating Circular 6.

[35] W. Du, C. Huang, and D. Scharfstein. Competing rails for cross-border payments: Banks, fintechs, and stablecoins. Harvard Business School working paper, 15 February 2026. Harvard Business School paper.

[36] Committee on Payments and Market Infrastructures and Board of the International Organization of Securities Commissions. Application of the Principles for Financial Market Infrastructures to stablecoin arrangements. Bank for International Settlements, July 2022. BIS report.

[37] R. Lorgat. One Entity in Many Jurisdictions. Companion paper, September 2026.

[38] R. Lorgat. Op: A Typed Bytecode for Compliance-Carrying Operations. Companion paper, September 2026.

[39] R. Lorgat. Admissible Obligation Transitions. Companion paper, September 2026.

[40] R. Lorgat. Event-Collect BFT. Companion paper, September 2026.

[41] S. Boucheron, G. Lugosi, and P. Massart. Concentration Inequalities: A Nonasymptotic Theory of Independence. Oxford University Press, 2013.

[42] R. Cont and T. Kokholm. Central clearing of OTC derivatives: Bilateral vs multilateral netting. Statistics and Risk Modeling, 31(1):3-22, 2014.

[43] D. Duffie and H. Zhu. Does a central clearing counterparty reduce counterparty risk? Review of Asset Pricing Studies, 1(1):74-95, 2011.

[44] D. Murphy. OTC Derivatives: Bilateral Trading and Central Clearing. Palgrave Macmillan, 2013.

[45] J. A. Cruz Lopez, J. H. Harris, C. Hurlin, and C. Pérignon. CoMargin. Journal of Financial and Quantitative Analysis, 52(5):2183-2215, 2017.

[46] S. Ghamami and P. Glasserman. Does OTC derivatives reform incentivize central clearing? Journal of Banking and Finance, 76:127-140, 2017.

[47] B. Biais, F. Heider, and M. Hoerova. Risk-sharing or risk-taking? Counterparty risk, incentives, and margins. Journal of Finance, 71(4):1669-1698, 2016.

[48] Committee on Payment and Settlement Systems and Technical Committee of the International Organization of Securities Commissions. Principles for Financial Market Infrastructures. Bank for International Settlements and IOSCO, April 2012. BIS publication page.

[49] European Parliament and Council. Regulation (EU) No 648/2012 of 4 July 2012 on OTC derivatives, central counterparties and trade repositories (EMIR); Commission Delegated Regulation (EU) No 153/2013 on regulatory technical standards on requirements for CCPs. Official Journal of the European Union, L 201:1-59, 2012; L 52:41-74, 2013.

[50] European Parliament and Council. Regulation (EU) No 648/2012, consolidated text of 17 January 2025, Articles 42–44. EUR-Lex consolidated text. ESMA, Article 44: liquidity risk controls.

[51] European Securities and Markets Authority. Question and Answer 880: CCP default-fund stress scenarios and client positions. ESMA Q&A 880.

[52] U.S. Congress. Dodd-Frank Wall Street Reform and Consumer Protection Act, Title VIII: Payment, Clearing, and Settlement Supervision. Public Law 111-203, 124 Stat. 1376, 2010.

[53] A. Evans, G. Angeris, and T. Chitra. Optimal fees for geometric mean market makers. In Financial Cryptography and Data Security 2021 Workshops, Lecture Notes in Computer Science 12676, Springer, pages 65-79, 2021.

[54] J. Milionis, C. C. Moallemi, T. Roughgarden, and A. L. Zhang. Automated market making and loss-versus-rebalancing. arXiv preprint arXiv:2208.06046, 2022.

[55] F. Allen and D. Gale. Financial contagion. Journal of Political Economy, 108(1):1-33, 2000.

[56] D. Bertsimas and A. W. Lo. Optimal control of execution costs. Journal of Financial Markets, 1(1):1-50, 1998.

[57] M. Krupa and P. Szmolyan. Relaxation oscillation and canard explosion. Journal of Differential Equations, 174(2):312-368, 2001.

[58] D. X. Li. On default correlation: A copula function approach. Journal of Fixed Income, 9(4):43-54, 2000.

[59] R. Lorgat. The Claim as Primitive. Companion paper, September 2026.

[60] C. Acerbi and D. Tasche. On the coherence of Expected Shortfall. Journal of Banking and Finance, 26(7):1487-1503, 2002.

[61] S. R. Howard, A. Ramdas, J. McAuliffe, and J. Sekhon. Time-uniform Chernoff bounds via nonnegative supermartingales. Probability Surveys, 17:257–317, 2020. Published article, Lemma 1.

[62] S. R. Howard, A. Ramdas, J. McAuliffe, and J. Sekhon. Time-uniform, nonparametric, nonasymptotic confidence sequences. Annals of Statistics, 49(2):1055–1080, 2021. Published article.

[63] R. Lorgat. Parlay Ising Couplings. Companion paper, September 2026.

[64] B. P. Welford. Note on a method for calculating corrected sums of squares and products. Technometrics, 4(3):419-420, 1962.

[65] M. Peters and J. Ye. A convex optimisation formulation of parimutuel mechanisms. Stanford University working paper, 2006.

[66] I. Csiszár and J. Körner. Information Theory: Coding Theorems for Discrete Memoryless Systems. Cambridge University Press, 2nd edition, 2011.

[67] D. T. Breeden and R. H. Litzenberger. Prices of state-contingent claims implicit in option prices. Journal of Business, 51(4):621-651, 1978.

[68] D. MacKenzie and T. Spears. “The formula that killed Wall Street”: The Gaussian copula and modelling practices in investment banking. Social Studies of Science, 44(3):393-417, 2014.

[69] F. Salmon. Recipe for disaster: The formula that killed Wall Street. Wired, 17(3), February 2009.

[70] A. Shapiro. Time consistency of dynamic risk measures. Operations Research Letters, 40(6):436–439, 2012. Journal article.